is there anyway to create a file with a list of IP's that i can use in the search field? i am trying to search for IP's that are not in this specific list but i don't want to create the list for every search.
For instance if i want to look through zeek conn.log for bad_guy IP's from a predefined list of bad guy IP's.
Thank you for any help.
i saw the lookup tables. i will try to figure them out. never used them before. kinda still learning Splunk.
TY
Read about "outputlookup" command to dynamically build your lookup from your search (https://docs.splunk.com/Documentation/Splunk/8.2.5/SearchReference/Outputlookup).
Here is a reference on how to use lookup as search filter: https://community.splunk.com/t5/Alerting/How-to-do-a-filtered-list-out-of-a-lookup-table/m-p/257806
You could consider creating a lookup table with the bad ip addresses, and using that to filter your search