Splunk Search

Cloud Provisioning Activity from Unusual Country - SPL search not working

jaibalaraman
Path Finder

Hi 

Can anyone help me why the below search is not working. 

index=aws sourcetype=aws:cloudtrail eventName=Create* OR eventName=Run* OR eventName=Attach* 
|stats count by src eventName 
| iplocation src

 

Thanks

0 Karma

kennetkline
Path Finder

Search is working for me;  against my AWS dataset

By not working (no results) or just no iplocation lookup??

Try iterative approach

1.  Search  ensure results:  (expand time window as necessary)

 

index=aws sourcetype=aws:cloudtrail ( eventName=Create* OR eventName=Run* OR eventName=Attach* )

 

2.   added your stats count by src, eventName

I assume you are getting ip's and not hostname's in the src field  (well a single IP).

3.  If the src's is somehow a multivalue,  (multipe ips) something your are going to need an mvexpand, split if comma separated or something.  It hast to be getting a single ip per row.


4.  | iplocation src

Hope this helps.



0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...