Splunk Search

Finding new IP addresses that haven't been seen before.

help_me_pls
New Member

Hey,
I have a splunk instance digesting nmap results. Each host that is found on the network generates an event that has information like IP and MAC addresses.

How can I formulate a search that would show me MAC addresses that were discovered for the first time in the last day or so?

I tried doing something like this:

 

NOT ([search earliest=-30d latest=-1d | table mac]) | table mac ip_address hostname

 

But that didn't actually remove any hosts that had been seen before.

 

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Have you tried a more explicit search?

index=nmap_index earliest=-1d NOT ([search index=nmap_index earliest=-30d latest=-1d | fields mac | format]) 
| table mac ip_address hostname
---
If this reply helps you, an upvote would be appreciated.
0 Karma
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!