Splunk Search

Expanding on a search result automatically

Eldad
Explorer

Hi,

I am trying to figure out how to achieve something and would appreciate any help from your experience.

I have a view showing some search results. There are two extracted fields. One is source IP address and the second is destination IP address. Now let's say I search for all events that have a certain destination IP address. I can easily get all extracted source IP addresses. Now the tricky part: I want to search for all events with the extracted source IP address and for those events extract all destination IP addresses. Today I need to do this manually, copy each source IP into a new search, extract the destination IPs and then again copy them one by one into a new search.

Is there an easier way to do this? If not, is it possible to add this functionality by myself?

Thanks for the help!

Tags (2)
1 Solution

sideview
SplunkTrust
SplunkTrust

I think for this you will need a subsearch. It will look something like this:

foo [ search destip=216.248.156.24 | dedup srcip | fields srcip ]

With a subsearch, splunkd will run the search within the brackets, and then the rows and fields of the subsearch get automatically turned into a boolean expression.

The end result is that splunkd will run this search:

foo ( srcip=A OR srcip=B OR srcip=C OR srcip=D OR ...... )

which I think is what you want.

View solution in original post

sideview
SplunkTrust
SplunkTrust

I think for this you will need a subsearch. It will look something like this:

foo [ search destip=216.248.156.24 | dedup srcip | fields srcip ]

With a subsearch, splunkd will run the search within the brackets, and then the rows and fields of the subsearch get automatically turned into a boolean expression.

The end result is that splunkd will run this search:

foo ( srcip=A OR srcip=B OR srcip=C OR srcip=D OR ...... )

which I think is what you want.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...