<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to search comunication between a inputlookup with some ip's  and traffic of an index ? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-comunication-between-a-inputlookup-with-some-ip-s/m-p/371126#M164042</link>
    <description>&lt;P&gt;Hi lguinn, thanks for your answer.   &lt;/P&gt;

&lt;P&gt;i add some data, thanks. &lt;/P&gt;

&lt;P&gt;What are you trying to accomplish? Do you want to see events from your indexes that match the ip addresses in the lookup table?&lt;BR /&gt;&lt;BR /&gt;
&lt;STRONG&gt;Yeah, i'm looking if some ip are doing match with the data from the inputlookp because the ip´s are identify like bad ip's, and the input only have two fields: ip and info.&lt;/STRONG&gt; &lt;BR /&gt;
What data is in the lookup table? Is it just a list of ip addresses? &lt;BR /&gt;
&lt;STRONG&gt;In the input are ip´s identify as indicator of compromise from a botnet.&lt;/STRONG&gt; &lt;BR /&gt;
What data is in the indexes?&lt;BR /&gt;
&lt;STRONG&gt;In the index are logs from a firewall with fiel like ip_src, ip_dst, service, protocol, etc...&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 17:29:02 GMT</pubDate>
    <dc:creator>Said7</dc:creator>
    <dc:date>2020-09-29T17:29:02Z</dc:date>
    <item>
      <title>How to search comunication between a inputlookup with some ip's  and traffic of an index ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-comunication-between-a-inputlookup-with-some-ip-s/m-p/371122#M164038</link>
      <description>&lt;P&gt;Hi, I have a doubt  about an inputlookup, i have a inputlookup with some ip's and i want to know how can see  comunication between my input and traffic from others indexes? &lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 16:00:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-comunication-between-a-inputlookup-with-some-ip-s/m-p/371122#M164038</guid>
      <dc:creator>Said7</dc:creator>
      <dc:date>2018-01-03T16:00:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to search comunication between a inputlookup with some ip's  and traffic of an index ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-comunication-between-a-inputlookup-with-some-ip-s/m-p/371123#M164039</link>
      <description>&lt;P&gt;The index are from a Firewall and i want search comunication between them, and then make a table with some interenting fields.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 16:05:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-comunication-between-a-inputlookup-with-some-ip-s/m-p/371123#M164039</guid>
      <dc:creator>Said7</dc:creator>
      <dc:date>2018-01-03T16:05:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to search comunication between a inputlookup with some ip's  and traffic of an index ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-comunication-between-a-inputlookup-with-some-ip-s/m-p/371124#M164040</link>
      <description>&lt;P&gt;There is no "communication" between data in Splunk.&lt;/P&gt;

&lt;P&gt;If you have a lookup table, you can use the inputlookup command (along with other commands) to combine the lookup table data with the events retrieved from indexes.&lt;/P&gt;

&lt;P&gt;However, this is a very general statement. There is no way to answer your question without more details.&lt;/P&gt;

&lt;P&gt;What are you trying to accomplish? Do you want to see events from your indexes that match the ip addresses in the lookup table? &lt;BR /&gt;
What data is in the lookup table? Is it just a list of ip addresses? &lt;BR /&gt;
What data is in the indexes?&lt;/P&gt;

&lt;P&gt;If you can answer these questions, and provide a bit of sample data, the community can help.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 20:15:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-comunication-between-a-inputlookup-with-some-ip-s/m-p/371124#M164040</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2018-01-03T20:15:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to search comunication between a inputlookup with some ip's  and traffic of an index ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-comunication-between-a-inputlookup-with-some-ip-s/m-p/371125#M164041</link>
      <description>&lt;P&gt;Said7, are you asking how to use a lookup table and incorporate it into a search of the Firewall traffic that you have being sent to your Splunk instance?&lt;/P&gt;

&lt;P&gt;Thanks!&lt;BR /&gt;
Glenn&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 20:24:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-comunication-between-a-inputlookup-with-some-ip-s/m-p/371125#M164041</guid>
      <dc:creator>gmchenry</dc:creator>
      <dc:date>2018-01-03T20:24:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to search comunication between a inputlookup with some ip's  and traffic of an index ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-comunication-between-a-inputlookup-with-some-ip-s/m-p/371126#M164042</link>
      <description>&lt;P&gt;Hi lguinn, thanks for your answer.   &lt;/P&gt;

&lt;P&gt;i add some data, thanks. &lt;/P&gt;

&lt;P&gt;What are you trying to accomplish? Do you want to see events from your indexes that match the ip addresses in the lookup table?&lt;BR /&gt;&lt;BR /&gt;
&lt;STRONG&gt;Yeah, i'm looking if some ip are doing match with the data from the inputlookp because the ip´s are identify like bad ip's, and the input only have two fields: ip and info.&lt;/STRONG&gt; &lt;BR /&gt;
What data is in the lookup table? Is it just a list of ip addresses? &lt;BR /&gt;
&lt;STRONG&gt;In the input are ip´s identify as indicator of compromise from a botnet.&lt;/STRONG&gt; &lt;BR /&gt;
What data is in the indexes?&lt;BR /&gt;
&lt;STRONG&gt;In the index are logs from a firewall with fiel like ip_src, ip_dst, service, protocol, etc...&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:29:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-comunication-between-a-inputlookup-with-some-ip-s/m-p/371126#M164042</guid>
      <dc:creator>Said7</dc:creator>
      <dc:date>2020-09-29T17:29:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to search comunication between a inputlookup with some ip's  and traffic of an index ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-comunication-between-a-inputlookup-with-some-ip-s/m-p/371127#M164043</link>
      <description>&lt;P&gt;Hi Glenn, yeah i want to incorporate a search with the index from the Firewall and the inputlookup. In the input are ip´s identified as a part of a botnet. And in the index are data from a firewall.  First i want to see if there are comunication between the internal ip´s with the ip´s from the inputlookup and then could be create a dashboard or an alert. &lt;/P&gt;

&lt;P&gt;Thanks for you help. &lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 21:12:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-comunication-between-a-inputlookup-with-some-ip-s/m-p/371127#M164043</guid>
      <dc:creator>Said7</dc:creator>
      <dc:date>2018-01-03T21:12:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to search comunication between a inputlookup with some ip's  and traffic of an index ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-comunication-between-a-inputlookup-with-some-ip-s/m-p/371128#M164044</link>
      <description>&lt;P&gt;This &lt;A href="https://answers.splunk.com/answers/608116/palo-alto-inputlookup-errors.html"&gt;recent answers post&lt;/A&gt; may help you.&lt;/P&gt;

&lt;P&gt;It contains a nice detailed example of searching IP address indicators from a lookup file.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 21:14:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-comunication-between-a-inputlookup-with-some-ip-s/m-p/371128#M164044</guid>
      <dc:creator>micahkemp</dc:creator>
      <dc:date>2018-01-03T21:14:54Z</dc:date>
    </item>
  </channel>
</rss>

