Splunk Enterprise Security

how do i get complete list of ip address ? is there any query ?

naveenyadav99
Explorer

i need to create a dashboard with complete information of IP address

0 Karma

kmorris_splunk
Splunk Employee
Splunk Employee

If you are just trying to get a distinct list of all IPs in your data, then you could do something simple like:

YOUR BASE SEARCH |
| eval allips = coalesce(src_ip,dest_ip) 
| stats count by allips 
| fields - count

This is an example giving a unique list of all IPs that showed up in the two fields in the coalesce command. Coalesce merges the fields specified into the field you create in the eval.

Get Updates on the Splunk Community!

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...

Security Newsletter Updates | March 2023

 March 2023 | Check out the latest and greatestUnify Your Security Operations with Splunk Mission Control The ...