Splunk Search

Creating visualization of list of ip address

andrewhlui
Explorer

I have data that has multiple (and variable) ip addresses associated with each event.

For example:
ABCD September 11, 2017 123.123.123.3 234.234.234.234.3
SDFG September 11, 2017 234.234.234.1 23.235.243.3 345.6.74.12

I am trying to create a map of IPs with geostats.

I tried doing index = abc | values(ip_addresses) | iplocation ip_addresses | geostats count by Country but that didn't seem to work - I think iplocation doesn't work with lists.

Any recommendations?

0 Karma
1 Solution

niketn
Legend

Use mvexpand to convert from multivalue to single value. Try the following:

index = abc 
| stats values(ip_addresses) as ip_addresses 
| mvexpand ip_addresses 
| iplocation ip_addresses 
| geostats count by Country
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

0 Karma

niketn
Legend

Use mvexpand to convert from multivalue to single value. Try the following:

index = abc 
| stats values(ip_addresses) as ip_addresses 
| mvexpand ip_addresses 
| iplocation ip_addresses 
| geostats count by Country
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...