Hi All
I would like run different search for a particular IP address. For example, a dashboard including a text box. you write your ip and see the results belongs to different searches regarding the ip. How are the main steps to do that?
Listing activity for a particular ip
Any help is appreciated.
Thanks
Use XML to have an input field that sets a variable, and then each search on the page contains that variable where it needs to be.
For example:
<fieldset>
<input type="text" token="ipaddress">
<label>IP</label>
</input>
</fieldset>
Then your search might be:
<searchString>
|search $ipaddress | chart ....
</searchString>
etc...
Use XML to have an input field that sets a variable, and then each search on the page contains that variable where it needs to be.
For example:
<fieldset>
<input type="text" token="ipaddress">
<label>IP</label>
</input>
</fieldset>
Then your search might be:
<searchString>
|search $ipaddress | chart ....
</searchString>
etc...
You are going to want to review this page: http://docs.splunk.com/Documentation/Splunk/5.0.3/Viz/Exampleform
. Each Situation is different, but essentially, you want to make a simple form with some tables that execute the search based off of the inputted IP address.