I am very new to Splunk and trying to gain as much knowledge as possible. I found there is an App called Splunk Global Threat Lankscape/Ip Watch List which I installed but I am getting zero results. I most definitely feel I should be seeing some type of results. Is anyone familiar with this app that can provide some feedback?
Try including an index name (which the app developer should have done for you).
index=main sourcetype="ip_watchlist"
|dedup offending_ip
|rename offending_ip as ip
|iplocation ip
|geostats globallimit=0 count by ip
If that fails, try this minimal query to see if the data is available.
index=* sourcetype="ip_watchlist"
What exactly are you doing when you get "zero results"? What results are you expecting?
Thanks for the reply, I am opening the "Splunk Global Threat Landscape/IP Watch list" app and nothing is displaying. I am also selecting the "Open in Search" of the map and receive zero events. The search that is created is as follows:
sourcetype="ip_watchlist" |dedup offending_ip|rename offending_ip as ip|iplocation ip|geostats globallimit=0 count by ip
I also found that running just the sourcetype="ip_watchlist" search gives me 0 events.
Try including an index name (which the app developer should have done for you).
index=main sourcetype="ip_watchlist"
|dedup offending_ip
|rename offending_ip as ip
|iplocation ip
|geostats globallimit=0 count by ip
If that fails, try this minimal query to see if the data is available.
index=* sourcetype="ip_watchlist"