Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How can I do a cidrmatch against a datamodel field

$
0
0
I'm working with Enterprise Security and I'm trying to build/refine correlations against the Network Traffic Data Model. I want to exclude destination addresses in RFC1918 space. When working with the Data Model, how do you express the equivalent of NOT cidrmatch ("172.16.0.0/20", All_Traffic.dest) Every combination I try gives me the error "Error in 'TsidxStats': WHERE clause is not an exact query"

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>