<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search in two table in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Search-in-two-table/m-p/567646#M197835</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;Finally find the right search:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=main host="xy2server" sourcetype="geo_ip_locations" earliest="08/24/2021:00:00:00" latest="08/24/2021:00:03:00" | table start_off finish_off Country "Alpha_2 code"
| join max=0 [search splunk_server="xyserver" index=main source="/var/log/ids.log" earliest=-24h@h | stats count by name, dest_ip, src_ip | sort –count
| eval ip_dot_decimal_split=split(src_ip,".")
| eval first=mvindex(ip_dot_decimal_split,0),second=mvindex(ip_dot_decimal_split,1),third=mvindex(ip_dot_decimal_split,2),fourth=mvindex(ip_dot_decimal_split,3)| fields - ip_dot_decimal_split
| eval first=first*pow(256,3),second=second*pow(256,2),third=third*256
| eval ip_address_integer=first+second+third+fourth
| table name src_ip dest_ip ip_address_integer] | where ip_address_integer&amp;gt;=start_off and ip_address_integer&amp;lt;=finish_off
| fields - start_off, finish_off, ip_address_integer
| table name dest_ip src_ip Country "Alpha_2 code"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 20 Sep 2021 11:56:33 GMT</pubDate>
    <dc:creator>AnnexQ</dc:creator>
    <dc:date>2021-09-20T11:56:33Z</dc:date>
    <item>
      <title>Search in two table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-in-two-table/m-p/564721#M196712</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I have two table.&lt;BR /&gt;The first have few ip what i switched dotdecimal&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk_server="xyserver" index=main
source="/var/log/ids.log" earliest=-24h | stats count by name, dest_ip, src_ip | sort –count
| eval ip_dot_decimal_split=split(src_ip,".")
| eval first=mvindex(ip_dot_decimal_split,0),second=mvindex(ip_dot_decimal_split,1),third=mvindex(ip_dot_decimal_split,2),fourth=mvindex(ip_dot_decimal_split,3)| fields - ip_dot_decimal_split
| eval first=first*pow(256,3),second=second*pow(256,2),third=third*256
| eval ip_address_integer=first+second+third+fourth
| fields - first,second,third,fourth&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The second table is a geoIP database (this is a static db)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=main host="xy2server" sourcetype="geo_ip_locations" earliest="08/24/2021:00:00:00" latest="08/24/2021:00:01:00" | table start_off finish_off "Alpha_2 code" Country&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The start_off and finish_off is&amp;nbsp;dotdecimal too.&lt;/P&gt;&lt;P&gt;I want to search the&amp;nbsp;ip_address_integer(created&amp;nbsp;dotdecimal) between predefined ip ranges (start_off / finish_off) and give me back the country and alpha2 values in new columns of the first table.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk Q.JPG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15728i86F9D3FF742AC3C7/image-size/large?v=v2&amp;amp;px=999" role="button" title="splunk Q.JPG" alt="splunk Q.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 13:39:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-in-two-table/m-p/564721#M196712</guid>
      <dc:creator>AnnexQ</dc:creator>
      <dc:date>2021-08-25T13:39:14Z</dc:date>
    </item>
    <item>
      <title>Re: Search in two table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-in-two-table/m-p/564729#M196716</link>
      <description>&lt;P&gt;You could append the second search, convert start_off to integer in the same field (ip_integer_address), then sort by ip_integer_address, and use filldown on the country and alpha2 fields.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 14:15:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-in-two-table/m-p/564729#M196716</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-08-25T14:15:11Z</dc:date>
    </item>
    <item>
      <title>Re: Search in two table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-in-two-table/m-p/564750#M196724</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;Thank you for your answer, but i think&amp;nbsp;this is not the solution I need or&amp;nbsp;I get it wrong.&lt;BR /&gt;&lt;BR /&gt;There is my two table:&lt;/P&gt;&lt;P&gt;First:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk ipai.JPG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15732iE2F2ADBFB2B90E4E/image-size/large?v=v2&amp;amp;px=999" role="button" title="splunk ipai.JPG" alt="splunk ipai.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I want add it to the first table the&amp;nbsp;appropriate value from the second table(Alpha2 &amp;amp; Country).&lt;BR /&gt;I need to find which country is where my ip falls in his range and add it to my first table as a new columns (A2 Code and Country).&lt;/P&gt;&lt;P&gt;Second&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="spunk geol.JPG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15733i927508FFEBE3543E/image-size/large?v=v2&amp;amp;px=999" role="button" title="spunk geol.JPG" alt="spunk geol.JPG" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Like this(edited picture):&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk2.jpg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15734iBFD2AB9C011A3963/image-size/large?v=v2&amp;amp;px=999" role="button" title="splunk2.jpg" alt="splunk2.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;(the values are not corret)&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;BR /&gt;AnnexQ&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 15:43:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-in-two-table/m-p/564750#M196724</guid>
      <dc:creator>AnnexQ</dc:creator>
      <dc:date>2021-08-25T15:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: Search in two table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-in-two-table/m-p/564761#M196730</link>
      <description>&lt;P&gt;It looks like you used appendcols rather than append - try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk_server="xyserver" index=main
source="/var/log/ids.log" earliest=-24h | stats count by name, dest_ip, src_ip | sort –count
| eval ip_dot_decimal_split=split(src_ip,".")
| eval first=mvindex(ip_dot_decimal_split,0),second=mvindex(ip_dot_decimal_split,1),third=mvindex(ip_dot_decimal_split,2),fourth=mvindex(ip_dot_decimal_split,3)| fields - ip_dot_decimal_split
| eval first=first*pow(256,3),second=second*pow(256,2),third=third*256
| eval ip_address_integer=first+second+third+fourth
| fields - first,second,third,fourth
| append [| search index=main host="xy2server" sourcetype="geo_ip_locations" earliest="08/24/2021:00:00:00" latest="08/24/2021:00:01:00" | table start_off finish_off "Alpha_2 code" Country | eval ip_dot_decimal_split=split(start_off ,".")
| eval first=mvindex(ip_dot_decimal_split,0),second=mvindex(ip_dot_decimal_split,1),third=mvindex(ip_dot_decimal_split,2),fourth=mvindex(ip_dot_decimal_split,3)| fields - ip_dot_decimal_split 
| eval first=first*pow(256,3),second=second*pow(256,2),third=third*256
| eval ip_address_integer=first+second+third+fourth
| fields - first,second,third,fourth]
| sort 0 ip_address_integer
| filldown Country 'Alpha_2 code'&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 16:34:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-in-two-table/m-p/564761#M196730</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-08-25T16:34:05Z</dc:date>
    </item>
    <item>
      <title>Re: Search in two table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-in-two-table/m-p/565236#M196922</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;Thanks for the help again&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;.&amp;nbsp;&lt;BR /&gt;Unfortunately i need another result.&lt;/P&gt;&lt;P&gt;I gott this table(with your search):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk.JPG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15788i5CF01D6676CE1338/image-size/large?v=v2&amp;amp;px=999" role="button" title="splunk.JPG" alt="splunk.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Off:&lt;BR /&gt;I gott same resoult whit this search:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk_server="xyserver" index=main
source="/var/log/ids.log" earliest=-24h | stats count by name, dest_ip, src_ip | sort –count
| eval ip_dot_decimal_split=split(src_ip,".")
| eval first=mvindex(ip_dot_decimal_split,0),second=mvindex(ip_dot_decimal_split,1),third=mvindex(ip_dot_decimal_split,2),fourth=mvindex(ip_dot_decimal_split,3)| fields - ip_dot_decimal_split
| eval first=first*pow(256,3),second=second*pow(256,2),third=third*256
| eval ip_address_integer=first+second+third+fourth
| union [ search index=main host="xy2server" sourcetype="geo_ip_locations" earliest="08/24/2021:00:00:00" latest="08/24/2021:00:03:00" | table start_off finish_off "Alpha_2 code" Country]
| fields - first,second,third,fourth&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;And i don't have idea, how to search the ip_address_integer values in the range&amp;nbsp; of start_off and Finish _off&amp;nbsp; and gett back the Country and A2code valoues in the first 4 line.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;From Two Tables, I would like to identify which country src-ip is from?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Aug 2021 13:30:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-in-two-table/m-p/565236#M196922</guid>
      <dc:creator>AnnexQ</dc:creator>
      <dc:date>2021-08-30T13:30:53Z</dc:date>
    </item>
    <item>
      <title>Re: Search in two table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-in-two-table/m-p/565297#M196951</link>
      <description>&lt;LI-CODE lang="markup"&gt;splunk_server="xyserver" index=main
source="/var/log/ids.log" earliest=-24h | stats count by name, dest_ip, src_ip | sort –count
| eval ip_dot_decimal_split=split(src_ip,".")
| eval first=mvindex(ip_dot_decimal_split,0),second=mvindex(ip_dot_decimal_split,1),third=mvindex(ip_dot_decimal_split,2),fourth=mvindex(ip_dot_decimal_split,3)| fields - ip_dot_decimal_split
| eval first=first*pow(256,3),second=second*pow(256,2),third=third*256
| eval ip_address_integer=first+second+third+fourth
| fields - first,second,third,fourth
| append [| search index=main host="xy2server" sourcetype="geo_ip_locations" earliest="08/24/2021:00:00:00" latest="08/24/2021:00:01:00" | table start_off finish_off "Alpha_2 code" Country
| eval ip_address_integer=start_off]
| sort 0 ip_address_integer
| filldown Country 'Alpha_2 code'&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 31 Aug 2021 09:16:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-in-two-table/m-p/565297#M196951</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-08-31T09:16:36Z</dc:date>
    </item>
    <item>
      <title>Re: Search in two table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-in-two-table/m-p/567646#M197835</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;Finally find the right search:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=main host="xy2server" sourcetype="geo_ip_locations" earliest="08/24/2021:00:00:00" latest="08/24/2021:00:03:00" | table start_off finish_off Country "Alpha_2 code"
| join max=0 [search splunk_server="xyserver" index=main source="/var/log/ids.log" earliest=-24h@h | stats count by name, dest_ip, src_ip | sort –count
| eval ip_dot_decimal_split=split(src_ip,".")
| eval first=mvindex(ip_dot_decimal_split,0),second=mvindex(ip_dot_decimal_split,1),third=mvindex(ip_dot_decimal_split,2),fourth=mvindex(ip_dot_decimal_split,3)| fields - ip_dot_decimal_split
| eval first=first*pow(256,3),second=second*pow(256,2),third=third*256
| eval ip_address_integer=first+second+third+fourth
| table name src_ip dest_ip ip_address_integer] | where ip_address_integer&amp;gt;=start_off and ip_address_integer&amp;lt;=finish_off
| fields - start_off, finish_off, ip_address_integer
| table name dest_ip src_ip Country "Alpha_2 code"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Sep 2021 11:56:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-in-two-table/m-p/567646#M197835</guid>
      <dc:creator>AnnexQ</dc:creator>
      <dc:date>2021-09-20T11:56:33Z</dc:date>
    </item>
  </channel>
</rss>

