Splunk Search

Comparing IP Addresses for differences

swright_rl
Explorer

Hi All,

I'm trying to create a search, to potentially be made into a monitoring rule later on.

What I am trying to achieve is a way to compare if a user has logged into his machine from a wildly different IP address.  This will be using external IP addresses only.

As an example I want to know if a user logged into the estate from an IP which wasn't the same or similar as the previous day.

 

UserTodayYesterday
User A155.123.1.1155.123.1.1
User B155.124.1.2155.125.20.2
User C155.166.2.522.18.254.56

 

In the table able, I have 3 users, user A and B have logged into pretty similar IP's although user B has logged in from a different one today ( this often happens in our logs ).  What I am more wanting to see is User C, who has logged into from a completely subnet IP and is not similar to their IP from the previous day. 

This is what I have so far:

 

index=foo (earliest=-1d@d latest=now())  
| eval TempClientIP=split(ForwardedClientIpAddress,",")
| eval ClientIP=mvindex(TempClientIP,0) 
|  eval ClientIP1=mvindex(TempClientIP,1) 
|  eval ClientIP2=mvindex(TempClientIP,2) 
| search NOT ClientIP=10.*
| where LIKE("ClientIP","ClientIP")
| eval when=if(_time<=relative_time(now(), "@d"), "Yesterday", "Today")
| chart values(ClientIP) over user by when 
|  where Yesterday!=Today

 

 

Some context regarding the search the ForwardedClientIpAddress field has 3 items inside, ClientIP + ClientIP1 are the same address, ClientIP2 is the end internal address. ClientIP can be an internal address, which is why there is a NOT to remove it from the searches.

 

Any help would be very much appreciated. 

 

Thanks

Labels (1)
Tags (3)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...