Getting Data In

Filter results by IP address

Explorer

Hi,

I have a search result that shows IP addresses that query a DNS server but how do I filter the search result to only show a particular host IP address.

The search so far just returns all results:

index="DNS-misc" sourcetype="named-query"

Thanks,

Tags (1)
0 Karma

SplunkTrust
SplunkTrust

Assuming the events contain the IP you're looking for and you want to show events containing 1.2.3.4 only you can do this:

index="DNS-misc" sourcetype="named-query" 1.2.3.4

If the filtered IP is extracted to a field, for example "host", you can do this:

index="DNS-misc" sourcetype="named-query" host=1.2.3.4
0 Karma