Security

IP Watch List

juanv
Engager

I am very new to Splunk and trying to gain as much knowledge as possible. I found there is an App called Splunk Global Threat Lankscape/Ip Watch List which I installed but I am getting zero results. I most definitely feel I should be seeing some type of results. Is anyone familiar with this app that can provide some feedback? 

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Try including an index name (which the app developer should have done for you).

index=main sourcetype="ip_watchlist" 
|dedup offending_ip
|rename offending_ip as ip
|iplocation ip
|geostats globallimit=0 count by ip

If that fails, try this minimal query to see if the data is available.

index=* sourcetype="ip_watchlist" 
---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What exactly are you doing when you get "zero results"?  What results are you expecting?

---
If this reply helps you, Karma would be appreciated.
0 Karma

juanv
Engager

Thanks for the reply, I am opening the "Splunk Global Threat Landscape/IP Watch list" app and nothing is displaying. I am also selecting the "Open in Search" of the map and receive zero events. The search that is created is as follows: 

sourcetype="ip_watchlist" |dedup offending_ip|rename offending_ip as ip|iplocation ip|geostats globallimit=0 count by ip

I also found that running just the sourcetype="ip_watchlist" search gives me 0 events. 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Try including an index name (which the app developer should have done for you).

index=main sourcetype="ip_watchlist" 
|dedup offending_ip
|rename offending_ip as ip
|iplocation ip
|geostats globallimit=0 count by ip

If that fails, try this minimal query to see if the data is available.

index=* sourcetype="ip_watchlist" 
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...