Splunk Search

Help with a simple search

agallegos
Engager

I am trying to do a search where by:

 

index=firewall (src_ip=172.16.0.0/12)  dest_ip!(172.16.0.0/12) | table src_ip src_port dest_ip dest_port | dedup src_ip

 

When I run this search I still see 172.16.0.0/12 destination IP addresses.  I've also tried it this way:

index=firewall (src_ip=172.16.0.0/12) NOT  dest_ip! IN (172.16.0.0/12) | table src_ip src_port dest_ip dest_port | dedup src_ip

Labels (3)
0 Karma

agallegos
Engager

Does it matter if the dedup was last or the second statement?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Putting dedup first allows the indexers to do part of the deduplication.  The table command, however, forces execution of the query back to the search head which then has to do all of the deduplication so having the dedup last is less performant.

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Assuming it's not just a typo in the question, the syntax is incorrect.  Try this:

index=firewall src_ip=172.16.0.0/12 dest_ip!=172.16.0.0/12 
| dedup src_ip
| table src_ip src_port dest_ip dest_port 
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...