Splunk Search

Help with a simple search

agallegos
Engager

I am trying to do a search where by:

 

index=firewall (src_ip=172.16.0.0/12)  dest_ip!(172.16.0.0/12) | table src_ip src_port dest_ip dest_port | dedup src_ip

 

When I run this search I still see 172.16.0.0/12 destination IP addresses.  I've also tried it this way:

index=firewall (src_ip=172.16.0.0/12) NOT  dest_ip! IN (172.16.0.0/12) | table src_ip src_port dest_ip dest_port | dedup src_ip

Labels (3)
0 Karma

agallegos
Engager

Does it matter if the dedup was last or the second statement?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Putting dedup first allows the indexers to do part of the deduplication.  The table command, however, forces execution of the query back to the search head which then has to do all of the deduplication so having the dedup last is less performant.

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Assuming it's not just a typo in the question, the syntax is incorrect.  Try this:

index=firewall src_ip=172.16.0.0/12 dest_ip!=172.16.0.0/12 
| dedup src_ip
| table src_ip src_port dest_ip dest_port 
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! 🌈 In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...