Getting Data In

Filter out my own source IP Address

Kai191
New Member

I have my search command as source="C:\Users\L30814\Desktop\1713.log" http | top 10 DestinationIP. What is the additional command to add in in order to filter out my own source IP Address??

0 Karma
1 Solution

gfuente
Motivator

Hello

You could try something like:

source="C:\Users\L30814\Desktop\1713.log" http NOT "xxx.xxx.xxx.xxx" |  top 10 DestinationIP

But this would filter any event with that ip adress, not just "source" adresses.

If you have the field extracted you can do it better with this command:

source="C:\Users\L30814\Desktop\1713.log" http AND c_ip!="xxx.xxx.xxx.xxx" |  top 10 DestinationIP

Supposing that you source ip adress is extracted in the field c_ip

Regards

View solution in original post

gfuente
Motivator

Hello

You could try something like:

source="C:\Users\L30814\Desktop\1713.log" http NOT "xxx.xxx.xxx.xxx" |  top 10 DestinationIP

But this would filter any event with that ip adress, not just "source" adresses.

If you have the field extracted you can do it better with this command:

source="C:\Users\L30814\Desktop\1713.log" http AND c_ip!="xxx.xxx.xxx.xxx" |  top 10 DestinationIP

Supposing that you source ip adress is extracted in the field c_ip

Regards

gfuente
Motivator

No problem

You can mark it as "Correct answer" if you think it´s correct. Thanks

0 Karma

Kai191
New Member

Thaks a lot!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...