Splunk Enterprise

Search IP events in a dynamic list of adress

faribole
Path Finder

I want to search for events related to a list of IPs that are declared on a public URL.
How can I insert this URL for ask this list in my Splunk request ?

 

 

 

Labels (1)
0 Karma

to4kawa
Ultra Champion

What kind of answer do you want?
You've asked how to do it, but you haven't written any information about it.

0 Karma

faribole
Path Finder

I only have the URL like https://name.com where I can obtain the list of IPs.

{
    "aws_eip_list": [
        "1.2.3.4",
        "1.2.3.4",
        "1.2.3.5"
]
}
 

 How to integer this information in a request

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...