Reporting

Creating subtotal counts of data from fields in the data using Splunk Enterprise

kentagous
Observer

Thanks in advance for the assistance, I am very new to Splunk it is a great tool but I need some assistance. 

I am trying to create a filtered report with the following criteria. 

- I am filtering the data down based on phishing, and now I need to grab each of the individual src_ip and count them.  over a 30 day period.  Unfortunately I do not know have a prelist of IP addresses based on all of the examples.   My goal is to go down the list and count the number of occurrences in this list and show the report on a front panel. 

Also, any good books or video training for learning how to do advanced filtering in Splunk. 

Thanks 

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @kentagous,

you can find many interesting videos in the YouTube Splunk Channel (https://www.youtube.com/@Splunkofficial).

then you can find many free courses at https://www.splunk.com/en_us/training/free-courses/overview.html

At least I hint to follow the Splunk Search Tutorial that helps you to understand how to create a search (https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchTutorial/WelcometotheSearchTutorial).

About your request, it depends on the data you have (fields).

So if you have the src_ip field in your index, you could run something like this:

index=your_index sourcetype=your_sourcetype earliest=-30d@d latest=now
| stats count BY src_ip

Ciao.

Giuseppe

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Assuming you already have the src_ip field already extracted correctly, you could try something like this

| stats count by src_ip
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...