Security

IP Watch List

juanv
Engager

I am very new to Splunk and trying to gain as much knowledge as possible. I found there is an App called Splunk Global Threat Lankscape/Ip Watch List which I installed but I am getting zero results. I most definitely feel I should be seeing some type of results. Is anyone familiar with this app that can provide some feedback? 

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Try including an index name (which the app developer should have done for you).

index=main sourcetype="ip_watchlist" 
|dedup offending_ip
|rename offending_ip as ip
|iplocation ip
|geostats globallimit=0 count by ip

If that fails, try this minimal query to see if the data is available.

index=* sourcetype="ip_watchlist" 
---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What exactly are you doing when you get "zero results"?  What results are you expecting?

---
If this reply helps you, Karma would be appreciated.
0 Karma

juanv
Engager

Thanks for the reply, I am opening the "Splunk Global Threat Landscape/IP Watch list" app and nothing is displaying. I am also selecting the "Open in Search" of the map and receive zero events. The search that is created is as follows: 

sourcetype="ip_watchlist" |dedup offending_ip|rename offending_ip as ip|iplocation ip|geostats globallimit=0 count by ip

I also found that running just the sourcetype="ip_watchlist" search gives me 0 events. 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Try including an index name (which the app developer should have done for you).

index=main sourcetype="ip_watchlist" 
|dedup offending_ip
|rename offending_ip as ip
|iplocation ip
|geostats globallimit=0 count by ip

If that fails, try this minimal query to see if the data is available.

index=* sourcetype="ip_watchlist" 
---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...