# Query field for set of values or not in set of values

**URL:** <https://discuss.elastic.co/t/query-field-for-set-of-values-or-not-in-set-of-values/176801>\
**Category:** Kibana\
**Created:** [April 14, 2019, 10:12pm UTC](https://discuss.elastic.co/t/query-field-for-set-of-values-or-not-in-set-of-values/176801 "2019-04-14T22:12:25Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![elasticSmash](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticsmash/32/45608_2.png) [@elasticSmash](https://discuss.elastic.co/u/elasticSmash)\
**Post date:** [April 14, 2019, 10:12pm UTC](https://discuss.elastic.co/t/query-field-for-set-of-values-or-not-in-set-of-values/176801/1 "2019-04-14T22:12:25Z")

</div>

It would be handy in Kibana to exclude a set of IP addresses without having to say !clientip:IP1 AND !clientip:IP2 AND ..... by doing something like clientip NOT IN [IP1, IP2, IP3] or being able to read the list of IPs to exclude from a saved table. Is there a way to do this?

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [April 15, 2019, 10:44pm UTC](https://discuss.elastic.co/t/query-field-for-set-of-values-or-not-in-set-of-values/176801/2 "2019-04-15T22:44:11Z")

</div>

It's not possible to do using a saved table, unfortunately.  
The "filter bar" in modern versions of Kibana makes this a bit easier.  
Also may be use DLS/FLS so they don’t return the data that has those fields/values?

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![elasticSmash](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticsmash/32/45608_2.png) [@elasticSmash](https://discuss.elastic.co/u/elasticSmash)\
**Post date:** [April 20, 2019, 11:26am UTC](https://discuss.elastic.co/t/query-field-for-set-of-values-or-not-in-set-of-values/176801/3 "2019-04-20T11:26:42Z")

</div>

It's good to know about DLS/FLS, but that's not a solution in this case. What I'm looking for is a way when running queries for doing log analysis to see the results that exclude a known list of hosts, such as the ones I'm responsible for. For instance, if I want to see all connections from IPs that are not my own or if I want to exclude connections that are to my database servers or something without having to enter every single IP or hostname. It would be handy to be able to reference them in some way. I could do a saved search, but then each saved search would need to be kept up to date.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 18, 2019, 11:26am UTC](https://discuss.elastic.co/t/query-field-for-set-of-values-or-not-in-set-of-values/176801/4 "2019-05-18T11:26:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
