Getting Data In

Find the common/same source ip (src) across several hosts with same sourcetype

Adrian
Path Finder

Require assistance to formulate a search which identifies the same source IP(src) across one or more hosts (opposite of unique value such as distinct count) with the same sourcetype

Need to answer this question: What source IP do these host(s) have in common?

sourcetype=x

host=a

host=b

host=c

host=d

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

I'm assuming you want to find IPs that occur in all four hosts.

sourcetype=x (host=a OR host=b OR host=c OR host=d) | stats dc(host) as dc by src | where dc==4

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

I'm assuming you want to find IPs that occur in all four hosts.

sourcetype=x (host=a OR host=b OR host=c OR host=d) | stats dc(host) as dc by src | where dc==4

Adrian
Path Finder

Final search looked something like this:

sourcetype="x" NOT src="0.0.0.0" (host="a" OR host="b" OR host="c" OR host="d")| stats dc(host) as dc by src | where dc>1 | sort - dc | lookup geoip clientip as src | fields - client_lat,client_lon,client_region,client_city | rename dc as "Clients Attacked" | rename client_country as Country

0 Karma

Adrian
Path Finder

Thanks Martin. That pretty much gets me where I need to be.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...