Splunk Enterprise

splunk SPL help

nnonm111
Path Finder

Please help sql when connecting to different IPs is successful.

filed list
ip -> src_ip
access -> success

(filed is You can change it to something comfortable.)

Labels (1)
Tags (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

I'm not sure if I understood your request correct, but maybe this helps you? If not, could you send some events so we could create your query based on those.

index=<your index> access=success
| dedup src_ip

This sample expects that you have field name access there which has values success or something else if connection didn't works.

r. Ismo 

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

Hi

I'm not sure if I understood your request correct, but maybe this helps you? If not, could you send some events so we could create your query based on those.

index=<your index> access=success
| dedup src_ip

This sample expects that you have field name access there which has values success or something else if connection didn't works.

r. Ismo 

nnonm111
Path Finder

If so, to view access success among IPs other than 192.168.10.11

index="my_index" src_ip=192.168.10.11 NOT src_ip access=success

Is it possible to do that?

0 Karma

isoutamo
SplunkTrust
SplunkTrust
index="my_index" src_ip!="192.168.10.11" access=success
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...