All Apps and Add-ons

Destination/Server IP in a log

jurij_hatala
New Member

Would it be possible to have a destination / server IP field in a log?
How it's could be configured?

0 Karma

PavelP
Motivator

Hello Jurij,
add to the log dest_ip=IP.toString(URL.dstIP)

Beware that this property triggers a DNS lookup.

Best regards
Pavel

0 Karma

jaxjohnny2000
Builder

Thank you. We'll try that

0 Karma

PavelP
Motivator

Hi

You need to enable dest ip rule in the mwgaccess3.log configuration. The rule is already there, just enable it.
Go policy > log handler > mwgaccess3.log

0 Karma

jaxjohnny2000
Builder

there is a field called "dest_ip", but it does not bring back those values:

value count %
1 116 16.089%
1132 4 0.555%
1125 3 0.416%
1188 3 0.416%
1438 3 0.416%
517 3 0.416%
6647 3 0.416%
6653 3 0.416%
1008 2 0.277%
1042 2 0.277%

0 Karma

jaxjohnny2000
Builder

the props.conf has this:
FIELDALIAS-dest_ip = dst AS dest_ip
REPORT-dst = mwg_dst

Does the Destination IP even come over from McAfee Web Gateway?

the src_ip field works fine.

When you say add to the log, I need to ask the McAfee admins to add this?

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...