Getting Data In

Find the common/same source ip (src) across several hosts with same sourcetype

Adrian
Path Finder

Require assistance to formulate a search which identifies the same source IP(src) across one or more hosts (opposite of unique value such as distinct count) with the same sourcetype

Need to answer this question: What source IP do these host(s) have in common?

sourcetype=x

host=a

host=b

host=c

host=d

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

I'm assuming you want to find IPs that occur in all four hosts.

sourcetype=x (host=a OR host=b OR host=c OR host=d) | stats dc(host) as dc by src | where dc==4

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

I'm assuming you want to find IPs that occur in all four hosts.

sourcetype=x (host=a OR host=b OR host=c OR host=d) | stats dc(host) as dc by src | where dc==4

Adrian
Path Finder

Final search looked something like this:

sourcetype="x" NOT src="0.0.0.0" (host="a" OR host="b" OR host="c" OR host="d")| stats dc(host) as dc by src | where dc>1 | sort - dc | lookup geoip clientip as src | fields - client_lat,client_lon,client_region,client_city | rename dc as "Clients Attacked" | rename client_country as Country

0 Karma

Adrian
Path Finder

Thanks Martin. That pretty much gets me where I need to be.

0 Karma
Get Updates on the Splunk Community!

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...

New Dates, New City: Save the Date for .conf25!

Wake up, babe! New .conf25 dates AND location just dropped!! That's right, this year, .conf25 is taking place ...

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...