Splunk Search

Is there anyway to create a file with a list of IP's that i can use in the search field?

tazzvon
Engager

is there anyway to create a file with a list of IP's that i can use in the search field? i am trying to search for IP's that are not in this specific list but i don't want to create the list for every search.

For instance if i want to look through zeek conn.log for bad_guy IP's from a predefined list of bad guy IP's.

Thank you for any help.

Labels (1)
0 Karma

tazzvon
Engager

i saw the lookup tables. i will try to figure them out. never used them before. kinda still learning Splunk.
TY

0 Karma

somesoni2
Revered Legend

Read about "outputlookup" command to dynamically build your lookup from your search (https://docs.splunk.com/Documentation/Splunk/8.2.5/SearchReference/Outputlookup). 

Here is a reference on how to use lookup as search filter: https://community.splunk.com/t5/Alerting/How-to-do-a-filtered-list-out-of-a-lookup-table/m-p/257806

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You could consider creating a lookup table with the bad ip addresses, and using that to filter your search

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...