You can do this using a lookup table (CSV) stored on the host server.
http://docs.splunk.com/Documentation/Splunk/5.0.3/Knowledge/Addfieldsfromexternaldatasources
You can then use a combination of an inputlookup command and subsearch in your search to filter these out.
http://docs.splunk.com/Documentation/Splunk/5.0.3/SearchReference/Inputlookup
http://docs.splunk.com/Documentation/Splunk/latest/Search/Aboutsubsearches
So (if my memory is correct - not done this is a little while), you could do something like:
<yourBaseSearch> NOT [|inputlookup <lookupFile> | fields + mac]
Hope this helps,
MHibbin
... View more