Splunk Enterprise

splunk SPL help

nnonm111
Path Finder

Please help sql when connecting to different IPs is successful.

filed list
ip -> src_ip
access -> success

(filed is You can change it to something comfortable.)

Labels (1)
Tags (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

I'm not sure if I understood your request correct, but maybe this helps you? If not, could you send some events so we could create your query based on those.

index=<your index> access=success
| dedup src_ip

This sample expects that you have field name access there which has values success or something else if connection didn't works.

r. Ismo 

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

Hi

I'm not sure if I understood your request correct, but maybe this helps you? If not, could you send some events so we could create your query based on those.

index=<your index> access=success
| dedup src_ip

This sample expects that you have field name access there which has values success or something else if connection didn't works.

r. Ismo 

nnonm111
Path Finder

If so, to view access success among IPs other than 192.168.10.11

index="my_index" src_ip=192.168.10.11 NOT src_ip access=success

Is it possible to do that?

0 Karma

isoutamo
SplunkTrust
SplunkTrust
index="my_index" src_ip!="192.168.10.11" access=success
Get Updates on the Splunk Community!

Why You Can't Miss .conf25: Unleashing the Power of Agentic AI with Splunk & Cisco

The Defining Technology Movement of Our Lifetime The advent of agentic AI is arguably the defining technology ...

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...