Splunk Enterprise Security

In Splunk Enterprise Security, how do you search for matching events between two groups of IP addresses?

jeremy_fade
New Member

I am trying to search for events that contain one IP from each of the two groups of IP addresses. For instance:

index=main sourcetype=* | 
search ("10.10.10.10" OR "30.30.30.30" OR "50.50.50.50" OR "70.70.70.70" OR "90.90.90.90") AND
("20.20.20.20" OR "40.40.40.40" OR "60.60.60.60" OR "80.80.80.80")

I am not specifying the source type or fields because I also want to search through multiple source types.

I couldn't find an answer similar to this issue. I also looked at subsearches, but didn't see how they would solve this.

0 Karma

valiquet
Contributor

index=main sourcetype=* | lookup ips AS ips OUTPUT ips1 ips2 | mvexpand ips1 ips2 | stats values(_raw) count DC(ips) AS dc by ips1,ips2 | where dc==1

I can't test it since you don't have logs.

0 Karma

cmerriman
Super Champion

is it possible for you to share some sample data and sample output of what you're looking for? scrubbed of pii/phi?

0 Karma

jeremy_fade
New Member

Negative. Company policy.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...