Splunk Search

Comparing IP Addresses for differences

swright_rl
Explorer

Hi All,

I'm trying to create a search, to potentially be made into a monitoring rule later on.

What I am trying to achieve is a way to compare if a user has logged into his machine from a wildly different IP address.  This will be using external IP addresses only.

As an example I want to know if a user logged into the estate from an IP which wasn't the same or similar as the previous day.

 

UserTodayYesterday
User A155.123.1.1155.123.1.1
User B155.124.1.2155.125.20.2
User C155.166.2.522.18.254.56

 

In the table able, I have 3 users, user A and B have logged into pretty similar IP's although user B has logged in from a different one today ( this often happens in our logs ).  What I am more wanting to see is User C, who has logged into from a completely subnet IP and is not similar to their IP from the previous day. 

This is what I have so far:

 

index=foo (earliest=-1d@d latest=now())  
| eval TempClientIP=split(ForwardedClientIpAddress,",")
| eval ClientIP=mvindex(TempClientIP,0) 
|  eval ClientIP1=mvindex(TempClientIP,1) 
|  eval ClientIP2=mvindex(TempClientIP,2) 
| search NOT ClientIP=10.*
| where LIKE("ClientIP","ClientIP")
| eval when=if(_time<=relative_time(now(), "@d"), "Yesterday", "Today")
| chart values(ClientIP) over user by when 
|  where Yesterday!=Today

 

 

Some context regarding the search the ForwardedClientIpAddress field has 3 items inside, ClientIP + ClientIP1 are the same address, ClientIP2 is the end internal address. ClientIP can be an internal address, which is why there is a NOT to remove it from the searches.

 

Any help would be very much appreciated. 

 

Thanks

Labels (1)
Tags (3)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Optimize AI at Scale: Must-Attend Observability Sessions at .conf26

conf26   With nearly 70 breakout sessions on the docket, the .conf26 Observability track is designed to help ...

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...