Security

IP Watch List

juanv
Engager

I am very new to Splunk and trying to gain as much knowledge as possible. I found there is an App called Splunk Global Threat Lankscape/Ip Watch List which I installed but I am getting zero results. I most definitely feel I should be seeing some type of results. Is anyone familiar with this app that can provide some feedback? 

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Try including an index name (which the app developer should have done for you).

index=main sourcetype="ip_watchlist" 
|dedup offending_ip
|rename offending_ip as ip
|iplocation ip
|geostats globallimit=0 count by ip

If that fails, try this minimal query to see if the data is available.

index=* sourcetype="ip_watchlist" 
---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What exactly are you doing when you get "zero results"?  What results are you expecting?

---
If this reply helps you, Karma would be appreciated.
0 Karma

juanv
Engager

Thanks for the reply, I am opening the "Splunk Global Threat Landscape/IP Watch list" app and nothing is displaying. I am also selecting the "Open in Search" of the map and receive zero events. The search that is created is as follows: 

sourcetype="ip_watchlist" |dedup offending_ip|rename offending_ip as ip|iplocation ip|geostats globallimit=0 count by ip

I also found that running just the sourcetype="ip_watchlist" search gives me 0 events. 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Try including an index name (which the app developer should have done for you).

index=main sourcetype="ip_watchlist" 
|dedup offending_ip
|rename offending_ip as ip
|iplocation ip
|geostats globallimit=0 count by ip

If that fails, try this minimal query to see if the data is available.

index=* sourcetype="ip_watchlist" 
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...