Splunk Search

Is there an inverse to the IN Command?

swright95
New Member

Hi Everyone,

I recently found the IN command

IP IN (10.72.168.*, 10.94.102.*, 10.80.134.*)  

I was curious if there was an inverse to the IN command, as it only seems to work with inclusive fields and not if you are "not" looking for something.

Just generally curious as this would clean up some of my queries rather than typing field!= all the time.

Thanks for advance.

Steve

0 Karma

woodcock
Esteemed Legend

The NOT operator should work on all logical functions, including IN so try NOT IN.

0 Karma

sbbadri
Motivator

May be you can try NOT IP IN (10.72.168., 10.94.102., 10.80.134.*)

0 Karma

somesoni2
Revered Legend

What version of Splunk you're using? In 6.6.0, something like this works fine.

...| where NOT IP IN ("x.x.x.x","y.y.y.y",....)
0 Karma
Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...