Splunk Search

Ignore List in a Macro

albyva
Communicator

If you create a search to watch network traffic and you wish to ignore a listing of /32 Destination IPs, would you create a macro of those IPs (ie: dest_ip=10.0.0.1/32) and then use
the NOT function in the search? For example:

Macro = whitelist
Search = index=generic NOT whitelist

Would this setup filter out all the IPs listed in the macro?

0 Karma

lukejadamec
Super Champion

Yes. But to call the macro you need backtacks NOT `whitelist`.

albyva
Communicator

Thanks. I actually do have the backtacks, but for some reason they aren't displaying in the Question. When I go to edit it, they appear and then disappear when saved. Weird. 🙂

AnyHoo... Thanks for the confirmation.

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...