Splunk Search

Expanding on a search result automatically

Eldad
Explorer

Hi,

I am trying to figure out how to achieve something and would appreciate any help from your experience.

I have a view showing some search results. There are two extracted fields. One is source IP address and the second is destination IP address. Now let's say I search for all events that have a certain destination IP address. I can easily get all extracted source IP addresses. Now the tricky part: I want to search for all events with the extracted source IP address and for those events extract all destination IP addresses. Today I need to do this manually, copy each source IP into a new search, extract the destination IPs and then again copy them one by one into a new search.

Is there an easier way to do this? If not, is it possible to add this functionality by myself?

Thanks for the help!

Tags (2)
1 Solution

sideview
SplunkTrust
SplunkTrust

I think for this you will need a subsearch. It will look something like this:

foo [ search destip=216.248.156.24 | dedup srcip | fields srcip ]

With a subsearch, splunkd will run the search within the brackets, and then the rows and fields of the subsearch get automatically turned into a boolean expression.

The end result is that splunkd will run this search:

foo ( srcip=A OR srcip=B OR srcip=C OR srcip=D OR ...... )

which I think is what you want.

View solution in original post

sideview
SplunkTrust
SplunkTrust

I think for this you will need a subsearch. It will look something like this:

foo [ search destip=216.248.156.24 | dedup srcip | fields srcip ]

With a subsearch, splunkd will run the search within the brackets, and then the rows and fields of the subsearch get automatically turned into a boolean expression.

The end result is that splunkd will run this search:

foo ( srcip=A OR srcip=B OR srcip=C OR srcip=D OR ...... )

which I think is what you want.

Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...