Hi there,
trying to exclude some events through the use of a lookup but it's not working for some reason:
index=main src_ip="192.168.0.0/16" (dest_ip!="127.0.0.1" OR dest_ip!="127.0.0.2") | dedup dest_ip | lookup dns.csv destdns_ip as dest_ip OUTPUTNEW query | search NOT [| inputlookup dns_excludes.csv | fields query ] | table dest_ip,query
dns.csv
dest_ip, query
127.0.0.5, windows.com
dns_excludes.csv
query
windows.com
It shows the data normally but doesn't exclude the dns_excludes.csv. Does anyone know what I'm doing wrong here?
What does your lookup table contains? (provide field names and their sample values)
Also, give this a try (query is a special keyword in Splunk, so avoiding that)
index=main src_ip="192.168.0.0/16" (dest_ip!="127.0.0.1" OR dest_ip!="127.0.0.2") | dedup dest_ip | lookup dns.csv destdns_ip as dest_ip OUTPUTNEW query as query1 | search NOT [| inputlookup dns_excludes.csv | fields query | rename query as query1 ]
rename query1 as query | table dest_ip,query
What does your lookup table contains? (provide field names and their sample values)
Also, give this a try (query is a special keyword in Splunk, so avoiding that)
index=main src_ip="192.168.0.0/16" (dest_ip!="127.0.0.1" OR dest_ip!="127.0.0.2") | dedup dest_ip | lookup dns.csv destdns_ip as dest_ip OUTPUTNEW query as query1 | search NOT [| inputlookup dns_excludes.csv | fields query | rename query as query1 ]
rename query1 as query | table dest_ip,query
This fixed it, thanks!
Hi @mmoermans, please accept this answer if it helped to solve your problem.
cheers, MuS