Splunk Search

Help with a simple search

agallegos
Engager

I am trying to do a search where by:

 

index=firewall (src_ip=172.16.0.0/12)  dest_ip!(172.16.0.0/12) | table src_ip src_port dest_ip dest_port | dedup src_ip

 

When I run this search I still see 172.16.0.0/12 destination IP addresses.  I've also tried it this way:

index=firewall (src_ip=172.16.0.0/12) NOT  dest_ip! IN (172.16.0.0/12) | table src_ip src_port dest_ip dest_port | dedup src_ip

Labels (3)
0 Karma

agallegos
Engager

Does it matter if the dedup was last or the second statement?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Putting dedup first allows the indexers to do part of the deduplication.  The table command, however, forces execution of the query back to the search head which then has to do all of the deduplication so having the dedup last is less performant.

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Assuming it's not just a typo in the question, the syntax is incorrect.  Try this:

index=firewall src_ip=172.16.0.0/12 dest_ip!=172.16.0.0/12 
| dedup src_ip
| table src_ip src_port dest_ip dest_port 
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...

Cloud Platform | Migrating your Splunk Cloud deployment to Python 3.7

Python 2.7, the last release of Python 2, reached End of Life back on January 1, 2020. As part of our larger ...