<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How do I search for IP address hitting a host? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/621097#M215908</link>
    <description />
    <pubDate>Thu, 17 Nov 2022 14:41:08 GMT</pubDate>
    <dc:creator>balu1211</dc:creator>
    <dc:date>2022-11-17T14:41:08Z</dc:date>
    <item>
      <title>How do I search for IP address hitting a host?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/621097#M215908</link>
      <description />
      <pubDate>Thu, 17 Nov 2022 14:41:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/621097#M215908</guid>
      <dc:creator>balu1211</dc:creator>
      <dc:date>2022-11-17T14:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: How do I Search for IP address hitting a Host ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/621098#M215909</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/250934"&gt;@balu1211&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;which Data Sources have you available (Firewall, VPN, network traffic, operative system, applications)?&lt;/P&gt;&lt;P&gt;Could you better describe your request?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 16:29:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/621098#M215909</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-16T16:29:20Z</dc:date>
    </item>
    <item>
      <title>Re: How do I Search for IP address hitting a Host ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/621104#M215912</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My use case is like findings the public ip addresses&amp;nbsp; hitting the WAF Host.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 16:50:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/621104#M215912</guid>
      <dc:creator>balu1211</dc:creator>
      <dc:date>2022-11-16T16:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: How do I Search for IP address hitting a Host ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/621108#M215913</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/250934"&gt;@balu1211&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I don't know if someone else is able to help you, but without information I don't know how to do it!&lt;/P&gt;&lt;P&gt;Please, share more information.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 17:00:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/621108#M215913</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-16T17:00:57Z</dc:date>
    </item>
    <item>
      <title>Re: How do I Search for IP address hitting a Host ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/621164#M215928</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a index waf in which i have to find out&amp;nbsp; the number of unique clientip , policyname,action by host name and adding lookup table in search to exclude ips of lookup table.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 02:29:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/621164#M215928</guid>
      <dc:creator>balu1211</dc:creator>
      <dc:date>2022-11-17T02:29:08Z</dc:date>
    </item>
    <item>
      <title>Re: How do I Search for IP address hitting a Host ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/621186#M215934</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/250934"&gt;@balu1211&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;ok, please try something like this (to adapt to your real fields):&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=waf NOT [ | inputlookup your_lookup | fields ip ]
| stats 
   dc(clientip) AS clientip_count
   values(clientip) AS clientip
   dc(policyname) AS policyname_count 
   values(policyname) AS policyname
   dc(action) AS action_count 
   values(action) AS action
   by host&lt;/LI-CODE&gt;&lt;P&gt;if you don't want the list of values of clientip, policyname and action, remove the values options.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 06:58:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/621186#M215934</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-17T06:58:21Z</dc:date>
    </item>
    <item>
      <title>Re: How do I Search for IP address hitting a Host ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/622140#M216254</link>
      <description>&lt;P&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 11:15:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/622140#M216254</guid>
      <dc:creator>balu1211</dc:creator>
      <dc:date>2022-12-14T11:15:38Z</dc:date>
    </item>
    <item>
      <title>Re: How do I Search for IP address hitting a Host ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/624165#M216996</link>
      <description>&lt;P&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 13:32:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/624165#M216996</guid>
      <dc:creator>balu1211</dc:creator>
      <dc:date>2022-12-15T13:32:40Z</dc:date>
    </item>
    <item>
      <title>Re: How do I Search for IP address hitting a Host ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/624192#M217010</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/250934"&gt;@balu1211&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;your search isn't optimized: don't use search after search, put all the serche terme in the main search to have a moro efficient search:&lt;/P&gt;&lt;P&gt;then, use quotes when you have spaces or special chars in field names (e.g. "Policy Name"), but probably it was a copy error.&lt;/P&gt;&lt;P&gt;Other than efficiency, what's the problem of your search?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=waf action_waf IN ("deny") NOT [ | inputlookup ipadd.csv | table IP | rename IP as "client_ip" | format ]
| lookup policyname.csv "Policy ID" OUTPUT "Policy Name"
| stats 
   values("Policy Name") AS "policy_name" 
   values(waf_rules) AS waf_rules
   values(message) AS message 
   count 
   BY client_ip action_waf&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 07:07:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/624192#M217010</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-12-14T07:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: How do I Search for IP address hitting a Host ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/624205#M217022</link>
      <description>&lt;P&gt;...&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 13:32:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/624205#M217022</guid>
      <dc:creator>balu1211</dc:creator>
      <dc:date>2022-12-15T13:32:01Z</dc:date>
    </item>
    <item>
      <title>Re: How do I search for IP address hitting a host?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/624206#M217023</link>
      <description>&lt;UL&gt;&lt;LI&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&lt;/LI&gt;&lt;LI&gt;In the output i need a whois on that IP like WHOIS.net url&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Wed, 14 Dec 2022 09:51:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/624206#M217023</guid>
      <dc:creator>balu1211</dc:creator>
      <dc:date>2022-12-14T09:51:51Z</dc:date>
    </item>
    <item>
      <title>Re: How do I Search for IP address hitting a Host ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/624261#M217042</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please look into this above scenario....&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 17:13:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/624261#M217042</guid>
      <dc:creator>balu1211</dc:creator>
      <dc:date>2022-12-14T17:13:10Z</dc:date>
    </item>
    <item>
      <title>Re: How do I Search for IP address hitting a Host ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/624265#M217044</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/250934"&gt;@balu1211&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;sorry but I don't understand: do you want to add ip_details that are in the&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;ip_add.csv lookup?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if this is your need, you could add a lookup command after the stats command.&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=waf action_waf IN ("deny") NOT [ | inputlookup ip_add.csv | table IP | rename IP as "client_ip" | format ]
| rename "attackData.clientIP" as "client_ip","attackData.policyId" as "Policy ID", "attackData.rules{}.message" as "message"
| lookup policyname.csv "Policy ID" OUTPUT "Policy Name"
| stats values(Policy Name) as "policy_name", values(waf_rules) as waf_rules,values(message) as message count by "client_ip","action_waf"
| lookup ip_add.csv IP AS client_ip OUTPUTNEW client_ip_details
| where count &amp;gt; 100
| fields + client_ip_details&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 17:33:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/624265#M217044</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-12-14T17:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: How do I Search for IP address hitting a Host ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/624280#M217049</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No my requirement is in the output of client ip i need there actual name eg.&lt;/P&gt;&lt;P&gt;2.58.56.101&lt;/P&gt;&lt;P&gt;If i search this in Arin site those details of client ip should get in output.&lt;/P&gt;&lt;P&gt;Pls refer to this link&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Search/Has-anyone-implemented-whois-lookups/m-p/148092#M41391" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Splunk-Search/Has-anyone-implemented-whois-lookups/m-p/148092#M41391&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You will get idea..&lt;/P&gt;&lt;P&gt;Mentioned app in the above link is not working for me so we have any alternative.&lt;/P&gt;&lt;P&gt;&amp;nbsp;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 20:53:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/624280#M217049</guid>
      <dc:creator>balu1211</dc:creator>
      <dc:date>2022-12-14T20:53:58Z</dc:date>
    </item>
    <item>
      <title>Re: How do I Search for IP address hitting a Host ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/624314#M217066</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/250934"&gt;@balu1211&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;the original link you shared isn't still available, so I don't understand your need.&lt;/P&gt;&lt;P&gt;Sorry.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 07:31:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/624314#M217066</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-12-15T07:31:00Z</dc:date>
    </item>
    <item>
      <title>Re: How do I Search for IP address hitting a Host ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/624327#M217071</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;Hi,&lt;/P&gt;&lt;P&gt;My use&amp;nbsp; case is in the below link &lt;A href="https://community.splunk.com/t5/Splunk-Search/Has-anyone-implemented-whois-lookups/m-p/148090" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Search/Has-anyone-implemented-whois-lookups/m-p/148090&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Pls get it how to implement the same in my search thanks..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 08:36:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/624327#M217071</guid>
      <dc:creator>balu1211</dc:creator>
      <dc:date>2022-12-15T08:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: How do I Search for IP address hitting a Host ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/624345#M217077</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/250934"&gt;@balu1211&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;yes but this solution refers to another answer (using Splunk 5!) that isn't available because too old.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 10:52:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/624345#M217077</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-12-15T10:52:34Z</dc:date>
    </item>
    <item>
      <title>Re: How do I Search for IP address hitting a Host ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/639913#M221740</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/250934"&gt;@balu1211&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 07:02:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-IP-address-hitting-a-host/m-p/639913#M221740</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-04-14T07:02:32Z</dc:date>
    </item>
  </channel>
</rss>

