Splunk Enterprise

splunk SPL help

nnonm111
Path Finder

Please help sql when connecting to different IPs is successful.

filed list
ip -> src_ip
access -> success

(filed is You can change it to something comfortable.)

Labels (1)
Tags (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

I'm not sure if I understood your request correct, but maybe this helps you? If not, could you send some events so we could create your query based on those.

index=<your index> access=success
| dedup src_ip

This sample expects that you have field name access there which has values success or something else if connection didn't works.

r. Ismo 

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

Hi

I'm not sure if I understood your request correct, but maybe this helps you? If not, could you send some events so we could create your query based on those.

index=<your index> access=success
| dedup src_ip

This sample expects that you have field name access there which has values success or something else if connection didn't works.

r. Ismo 

nnonm111
Path Finder

If so, to view access success among IPs other than 192.168.10.11

index="my_index" src_ip=192.168.10.11 NOT src_ip access=success

Is it possible to do that?

0 Karma

isoutamo
SplunkTrust
SplunkTrust
index="my_index" src_ip!="192.168.10.11" access=success
Get Updates on the Splunk Community!

Simplifying the Analyst Experience with Finding-based Detections

    Splunk invites you to an engaging Tech Talk focused on streamlining security operations with ...

[Puzzles] Solve, Learn, Repeat: Word Search

This challenge was first posted on Slack #puzzles channelThis puzzle is based on a letter grid containing ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 4

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...