Splunk Search

Cloud Provisioning Activity from Unusual Country - SPL search not working

jaibalaraman
Path Finder

Hi 

Can anyone help me why the below search is not working. 

index=aws sourcetype=aws:cloudtrail eventName=Create* OR eventName=Run* OR eventName=Attach* 
|stats count by src eventName 
| iplocation src

 

Thanks

Labels (1)
0 Karma

kennetkline
Path Finder

Search is working for me;  against my AWS dataset

By not working (no results) or just no iplocation lookup??

Try iterative approach

1.  Search  ensure results:  (expand time window as necessary)

 

index=aws sourcetype=aws:cloudtrail ( eventName=Create* OR eventName=Run* OR eventName=Attach* )

 

2.   added your stats count by src, eventName

I assume you are getting ip's and not hostname's in the src field  (well a single IP).

3.  If the src's is somehow a multivalue,  (multipe ips) something your are going to need an mvexpand, split if comma separated or something.  It hast to be getting a single ip per row.


4.  | iplocation src

Hope this helps.



0 Karma
Get Updates on the Splunk Community!

Five Subtly Different Ways of Adding Manual Instrumentation in Java

You can find the code of this example on GitHub here. Please feel free to star the repository to keep in ...

New Splunk APM Enhancements Help Troubleshoot Your MySQL and NoSQL Databases Faster

Splunk Observability has two new enhancements to make it quicker and easier to troubleshoot slow or frequently ...

How to Troubleshoot our Splunk HEC Endpoint

This blog post is part of an ongoing series on OpenTelemetry. In this blog post, we will explore the best way ...