<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic splunk internal logs, precisions on the &amp;quot;clientip&amp;quot; field in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/splunk-internal-logs-precisions-on-the-quot-clientip-quot-field/m-p/445537#M173902</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I want to list all Deployment client on a dashboard in my Search Head with the following request:&lt;BR /&gt;
index=_internal host="my Deployment Server" | dedup clientip |table clientip [...]&lt;/P&gt;

&lt;P&gt;In the result, I have the list of my Deployment Client, The Deployment Server, localhost loop and serveral proxy IP.&lt;/P&gt;

&lt;P&gt;The fowarding management of theses proxies aren't in my cluster then it's my Deployment Server which manage them. They are fully independant of my client pool and I don't collect their logs.&lt;BR /&gt;
In the fowarding management menu, I don't see these clients.&lt;/P&gt;

&lt;P&gt;What exactly contains the fields "clientip" of Splunk internal logs ? &lt;BR /&gt;
And why I see theses proxy address in my Deployment Server clientip ? any idea ? &lt;/P&gt;

&lt;P&gt;Thank you.&lt;BR /&gt;
Best regards&lt;/P&gt;</description>
    <pubDate>Wed, 26 Dec 2018 13:19:48 GMT</pubDate>
    <dc:creator>mabonjean</dc:creator>
    <dc:date>2018-12-26T13:19:48Z</dc:date>
    <item>
      <title>splunk internal logs, precisions on the "clientip" field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-internal-logs-precisions-on-the-quot-clientip-quot-field/m-p/445537#M173902</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I want to list all Deployment client on a dashboard in my Search Head with the following request:&lt;BR /&gt;
index=_internal host="my Deployment Server" | dedup clientip |table clientip [...]&lt;/P&gt;

&lt;P&gt;In the result, I have the list of my Deployment Client, The Deployment Server, localhost loop and serveral proxy IP.&lt;/P&gt;

&lt;P&gt;The fowarding management of theses proxies aren't in my cluster then it's my Deployment Server which manage them. They are fully independant of my client pool and I don't collect their logs.&lt;BR /&gt;
In the fowarding management menu, I don't see these clients.&lt;/P&gt;

&lt;P&gt;What exactly contains the fields "clientip" of Splunk internal logs ? &lt;BR /&gt;
And why I see theses proxy address in my Deployment Server clientip ? any idea ? &lt;/P&gt;

&lt;P&gt;Thank you.&lt;BR /&gt;
Best regards&lt;/P&gt;</description>
      <pubDate>Wed, 26 Dec 2018 13:19:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-internal-logs-precisions-on-the-quot-clientip-quot-field/m-p/445537#M173902</guid>
      <dc:creator>mabonjean</dc:creator>
      <dc:date>2018-12-26T13:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: splunk internal logs, precisions on the "clientip" field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-internal-logs-precisions-on-the-quot-clientip-quot-field/m-p/445538#M173903</link>
      <description>&lt;P&gt;To  see where the client IP addresses are coming from, try this search.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal TERM(clientip address goes here)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The results returned will show the host and source of the events as well as details of the event that sent the IP address.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Dec 2018 15:45:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-internal-logs-precisions-on-the-quot-clientip-quot-field/m-p/445538#M173903</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2018-12-26T15:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: splunk internal logs, precisions on the "clientip" field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-internal-logs-precisions-on-the-quot-clientip-quot-field/m-p/445539#M173904</link>
      <description>&lt;P&gt;I don't a forgotten elements in my question.&lt;BR /&gt;
I select the Deployment Server as host in my request.&lt;/P&gt;

&lt;P&gt;When I list all clientip, I have more client than I have in the Deployment Server.&lt;/P&gt;

&lt;P&gt;Ma main question is : what is "clientip" ? Which data does it contains ?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Dec 2018 16:06:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-internal-logs-precisions-on-the-quot-clientip-quot-field/m-p/445539#M173904</guid>
      <dc:creator>mabonjean</dc:creator>
      <dc:date>2018-12-26T16:06:55Z</dc:date>
    </item>
    <item>
      <title>Re: splunk internal logs, precisions on the "clientip" field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-internal-logs-precisions-on-the-quot-clientip-quot-field/m-p/445540#M173905</link>
      <description>&lt;P&gt;When you run the query in my original comment you'll get events containing the client IP addresses.  Close examination of the events should tell you why they're showing up.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Dec 2018 18:50:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-internal-logs-precisions-on-the-quot-clientip-quot-field/m-p/445540#M173905</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2018-12-26T18:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: splunk internal logs, precisions on the "clientip" field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-internal-logs-precisions-on-the-quot-clientip-quot-field/m-p/445541#M173906</link>
      <description>&lt;P&gt;This may help:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal host=&amp;lt;yourDS&amp;gt;  POST /services/broker/phonehome/connection | 
 rex field=uri "_(?&amp;lt;fwd_name&amp;gt;[^_]+)_(?&amp;lt;fwd_id&amp;gt;[-0-9A-Z]+)$" | 
 stats latest(eval(now()-_time)) as Latest earliest(eval(now()-_time)) as Earliest by fwd_name fwd_id clientip |
 rename clientip as fwd_ip
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 27 Dec 2018 05:56:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-internal-logs-precisions-on-the-quot-clientip-quot-field/m-p/445541#M173906</guid>
      <dc:creator>p_gurav</dc:creator>
      <dc:date>2018-12-27T05:56:06Z</dc:date>
    </item>
    <item>
      <title>Re: splunk internal logs, precisions on the "clientip" field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-internal-logs-precisions-on-the-quot-clientip-quot-field/m-p/445542#M173907</link>
      <description>&lt;P&gt;Thanks @p_gurav,&lt;BR /&gt;
Your request is really helpfull.&lt;BR /&gt;
With it, I can easily see what I want.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Dec 2018 09:23:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-internal-logs-precisions-on-the-quot-clientip-quot-field/m-p/445542#M173907</guid>
      <dc:creator>mabonjean</dc:creator>
      <dc:date>2018-12-27T09:23:20Z</dc:date>
    </item>
    <item>
      <title>Re: splunk internal logs, precisions on the "clientip" field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-internal-logs-precisions-on-the-quot-clientip-quot-field/m-p/445543#M173908</link>
      <description>&lt;P&gt;Great!!  Please accept  the answer if its helpful!!&lt;/P&gt;</description>
      <pubDate>Thu, 27 Dec 2018 09:48:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-internal-logs-precisions-on-the-quot-clientip-quot-field/m-p/445543#M173908</guid>
      <dc:creator>p_gurav</dc:creator>
      <dc:date>2018-12-27T09:48:35Z</dc:date>
    </item>
  </channel>
</rss>

