Hi
I want to read IP addresses from a Json file and manage the addresses that was read as a whitelist.
Whitelist where/what?
Hi @Aina
For field extractions on json data use spath command: http://docs.splunk.com/Documentation/Splunk/6.5.0/SearchReference/Spath
Export your fields of interest in CSV format (IPs in this case) with outputlookup command: http://docs.splunk.com/Documentation/Splunk/6.5.0/SearchReference/Outputlookup
You can then load that CSV into your query and use it like a whitelist with this commands, lookup, inputlookup: http://docs.splunk.com/Documentation/Splunk/6.5.0/SearchReference/Inputlookup
If this is not the help you were looking for please elaborate your question so that I can help you.
KR.