# Exclude a lost of mac addresses in alert with elasticsearch query

**URL:** <https://discuss.elastic.co/t/exclude-a-lost-of-mac-addresses-in-alert-with-elasticsearch-query/333590>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [May 16, 2023, 4:50pm UTC](https://discuss.elastic.co/t/exclude-a-lost-of-mac-addresses-in-alert-with-elasticsearch-query/333590 "2023-05-16T16:50:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![odelacruzc93](https://avatars.discourse-cdn.com/v4/letter/o/dc4da7/32.png) [@odelacruzc93](https://discuss.elastic.co/u/odelacruzc93)\
**Post date:** [May 16, 2023, 4:50pm UTC](https://discuss.elastic.co/t/exclude-a-lost-of-mac-addresses-in-alert-with-elasticsearch-query/333590/1 "2023-05-16T16:50:50Z")

</div>

Hi There! Please I need your help, I am ingesting logs ARP and DHCP to find IPs outside my porganizatión, so I implemented an alarm but I must exclude 1650 MAC addresses, can I create a list with these MAC addresses to add in the alarm with elasticsearch query without creating a very large query?

Currently my query in alarm is:

```auto
{
  "query": {
    "bool": {
        "must":[
        {
        "match":{ 
          "type": "device_packet_flood"
        }    
            
        }
         ]
    }
  }
}

```

But I have to filter 1650 addresses MAC for example:

```auto
{
  "query": {
    "bool": {
      "filter": [
        {
          "bool": {
            "should": [
              {
                "match_phrase": {
                  "type": "device_packet_flood"
                }
              }
            ]
          }
        }
      ],
      "must_not": [
        {
          "bool": {
            "should": [
              {
                "match_phrase": {
                  "device": "00:00:F6:CB:AC:51 OR 04:56:E5:7C:BB:4 OR etc OR etc OR etc OR etc (1650 MAcs)"
                }
              }
            ]
          }
        }
      ]
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [May 18, 2023, 9:40pm UTC](https://discuss.elastic.co/t/exclude-a-lost-of-mac-addresses-in-alert-with-elasticsearch-query/333590/2 "2023-05-18T21:40:25Z")

</div>

Perhaps the [Terms Lookup](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-terms-query.html#query-dsl-terms-lookup)?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 15, 2023, 9:41pm UTC](https://discuss.elastic.co/t/exclude-a-lost-of-mac-addresses-in-alert-with-elasticsearch-query/333590/3 "2023-06-15T21:41:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
