<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do i group the log for ip, or type? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-do-i-group-the-log-for-ip-or-type/m-p/62225#M15381</link>
    <description>&lt;P&gt;Im sorry if you couldn't understand me&lt;/P&gt;

&lt;P&gt;I mean I want to do a report  that tell me who attack me and which ip, things like that, but I have no idea how to group these events.&lt;/P&gt;</description>
    <pubDate>Mon, 17 Sep 2012 21:12:16 GMT</pubDate>
    <dc:creator>graidelak</dc:creator>
    <dc:date>2012-09-17T21:12:16Z</dc:date>
    <item>
      <title>How do i group the log for ip, or type?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-i-group-the-log-for-ip-or-type/m-p/62223#M15379</link>
      <description>&lt;P&gt;Hi I want to know how can i group my log from my firewall by source ip, or dest_ip or type, because i want to make a report that show me the attack or events by groups.&lt;/P&gt;

&lt;P&gt;Maybe is a stupid question but im just newbie using splunk and i want to learn how can i do that.&lt;/P&gt;

&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2012 20:38:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-i-group-the-log-for-ip-or-type/m-p/62223#M15379</guid>
      <dc:creator>graidelak</dc:creator>
      <dc:date>2012-09-17T20:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: How do i group the log for ip, or type?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-i-group-the-log-for-ip-or-type/m-p/62224#M15380</link>
      <description>&lt;P&gt;I am not sure I understand the question&lt;/P&gt;

&lt;P&gt;If you want statistics then take a look &lt;A href="http://splunk-base.splunk.com/answers/58911/show-column-as-count?page=1&amp;amp;focusedAnswerId=58942#58942"&gt;here&lt;/A&gt;:&lt;/P&gt;

&lt;P&gt;If you want these combined together, perhaps the &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Transaction"&gt;transaction search cmd&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2012 20:50:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-i-group-the-log-for-ip-or-type/m-p/62224#M15380</guid>
      <dc:creator>melting</dc:creator>
      <dc:date>2012-09-17T20:50:03Z</dc:date>
    </item>
    <item>
      <title>Re: How do i group the log for ip, or type?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-i-group-the-log-for-ip-or-type/m-p/62225#M15381</link>
      <description>&lt;P&gt;Im sorry if you couldn't understand me&lt;/P&gt;

&lt;P&gt;I mean I want to do a report  that tell me who attack me and which ip, things like that, but I have no idea how to group these events.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2012 21:12:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-i-group-the-log-for-ip-or-type/m-p/62225#M15381</guid>
      <dc:creator>graidelak</dc:creator>
      <dc:date>2012-09-17T21:12:16Z</dc:date>
    </item>
    <item>
      <title>Re: How do i group the log for ip, or type?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-i-group-the-log-for-ip-or-type/m-p/62226#M15382</link>
      <description>&lt;P&gt;Did you take the Splunk tutorial? It's a great way to get past the "I'm very new to Splunk" phase.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2012 21:16:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-i-group-the-log-for-ip-or-type/m-p/62226#M15382</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-09-17T21:16:02Z</dc:date>
    </item>
    <item>
      <title>Re: How do i group the log for ip, or type?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-i-group-the-log-for-ip-or-type/m-p/62227#M15383</link>
      <description>&lt;P&gt;Yeah I did but I can't group those events. Let me see if I can explain better.&lt;/P&gt;

&lt;P&gt;I want to see my firewall log (watchguard) and make some search by src_ip or dest_ip and then a report to see how many deny, attack, or error i had. &lt;/P&gt;

&lt;P&gt;I saw many apps for firewall but i didn't see one for watchguard firebox&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:27:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-i-group-the-log-for-ip-or-type/m-p/62227#M15383</guid>
      <dc:creator>graidelak</dc:creator>
      <dc:date>2020-09-28T12:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: How do i group the log for ip, or type?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-i-group-the-log-for-ip-or-type/m-p/62228#M15384</link>
      <description>&lt;P&gt;You'd need to create fields out of your logs (covered in the tutorial, tl;dr: use the interactive field extractor in splunkweb), and then grab stats on the fields you mention (also covered in the tutorial). If you want to create a search form that only requires you to input an IP number and automatically get charts, tables etc, have a look at the "Build forms" section of the developer manual).&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2012 21:55:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-i-group-the-log-for-ip-or-type/m-p/62228#M15384</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-09-17T21:55:38Z</dc:date>
    </item>
    <item>
      <title>Re: How do i group the log for ip, or type?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-i-group-the-log-for-ip-or-type/m-p/62229#M15385</link>
      <description>&lt;P&gt;query | chart by host&lt;/P&gt;

&lt;P&gt;by important part being "by host"&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2012 22:01:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-i-group-the-log-for-ip-or-type/m-p/62229#M15385</guid>
      <dc:creator>rogerdpack</dc:creator>
      <dc:date>2012-09-17T22:01:27Z</dc:date>
    </item>
  </channel>
</rss>

