Splunk Search

Create a list

rootadmin
New Member

Hi

Im very new to splunk (first day using it)

Is it possible to create a list of known mac addresses so that i can perform a search

so at the moment im searching for new wireless client associations against the router, i would like to put existing wireless clients into a list of known mac addresses to include a not statement to account for known mac addresses.

have this working currently by explicitly mentioning each mac address in the not statement

Tags (1)
0 Karma

MHibbin
Influencer

You can do this using a lookup table (CSV) stored on the host server.

http://docs.splunk.com/Documentation/Splunk/5.0.3/Knowledge/Addfieldsfromexternaldatasources

You can then use a combination of an inputlookup command and subsearch in your search to filter these out.

http://docs.splunk.com/Documentation/Splunk/5.0.3/SearchReference/Inputlookup
http://docs.splunk.com/Documentation/Splunk/latest/Search/Aboutsubsearches

So (if my memory is correct - not done this is a little while), you could do something like:

<yourBaseSearch> NOT [|inputlookup <lookupFile> | fields + mac]

Hope this helps,

MHibbin

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...