Splunk Enterprise

How do I set up a global whitelist?

kinomakino
New Member

First of all, thanks for the help.

I do not have much experience with Splunk.

I'm compiling security events, but I want to set up a high-level whitelist to include, for example, Microsoft's ip and other products that I consider legitimate. But I do not want them to appear in the queries and alerts.

Is there any elegant way to define a whitelist at a high level for all Splunk to omit data from this whitelist?

Would there be any way to do the opposite? For example, define a blacklist? Right now I do it for specific queries, for example consulting a CSV. But I mean something more global, for all the queries.

Thanks for the help.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...