Hi, Below is my splunk search query & Screenshot. I want eliminate TrustedLocation = "Zscaler Miami III" from my result. Please help me with splunk query. I tried but unable to acheive it. index=test "vendorInformation.provider"=IPC | eval Event_Date=mvindex('eventDateTime',0) | eval UPN=mvindex('userStates{}.userPrincipalName',0) | eval Logon_Location=mvindex('userStates{}.logonLocation',0) | eval Event_Title=mvindex('title',0) | eval Event_Severity=mvindex('severity',0) | eval AAD_Acct=mvindex('userStates{}.aadUserId',0) | eval LogonIP=mvindex('userStates{}.logonIp',0) | eval Investigate=+"https://portal.azure.com/#blade/Microsoft_AAD_IAM/RiskyUsersBlade/userId/".AAD_Acct | stats count by Event_Date, Event_Title, Event_Severity UPN Logon_Location LogonIP Investigate | lookup WeirMFAStatusLookup.csv userPrincipalName as UPN | lookup Lookup_EMPADInfo.csv userPrincipalName as UPN | lookup WeirSiteCode2IP.csv public_ip as LogonIP | lookup ZscalerIP CIDR_IP as LogonIP | lookup WeirTrustedIPs.csv TrustedIP as LogonIP | fillnull value="Unknown Site" site_code | eval AD_Location=st + ", " + c | fillnull value="OK" MFAStatus | eval TrustedLocation=if(isnull(TrustedLocation), ZLocation, TrustedLocation) | rename site_code as LogonSiteCode | table Event_Date, Event_Title, Event_Severity UPN LogonIP LogonSiteCode Logon_Location AD_Location TrustedLocation MFAStatus count Investigate | sort - Event_Date alexspunkshell_1-1608637515737.png @soutamo @ITWhisperer @gcusello @thambisetty @richgalloway @to4kawa
... View more