Splunk Search

Cloud Provisioning Activity from Unusual Country - SPL search not working

jaibalaraman
Path Finder

Hi 

Can anyone help me why the below search is not working. 

index=aws sourcetype=aws:cloudtrail eventName=Create* OR eventName=Run* OR eventName=Attach* 
|stats count by src eventName 
| iplocation src

 

Thanks

Labels (1)
0 Karma

kennetkline
Path Finder

Search is working for me;  against my AWS dataset

By not working (no results) or just no iplocation lookup??

Try iterative approach

1.  Search  ensure results:  (expand time window as necessary)

 

index=aws sourcetype=aws:cloudtrail ( eventName=Create* OR eventName=Run* OR eventName=Attach* )

 

2.   added your stats count by src, eventName

I assume you are getting ip's and not hostname's in the src field  (well a single IP).

3.  If the src's is somehow a multivalue,  (multipe ips) something your are going to need an mvexpand, split if comma separated or something.  It hast to be getting a single ip per row.


4.  | iplocation src

Hope this helps.



0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...