Splunk Search

Ignore List in a Macro

albyva
Communicator

If you create a search to watch network traffic and you wish to ignore a listing of /32 Destination IPs, would you create a macro of those IPs (ie: dest_ip=10.0.0.1/32) and then use
the NOT function in the search? For example:

Macro = whitelist
Search = index=generic NOT whitelist

Would this setup filter out all the IPs listed in the macro?

0 Karma

lukejadamec
Super Champion

Yes. But to call the macro you need backtacks NOT `whitelist`.

albyva
Communicator

Thanks. I actually do have the backtacks, but for some reason they aren't displaying in the Question. When I go to edit it, they appear and then disappear when saved. Weird. 🙂

AnyHoo... Thanks for the confirmation.

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.