Splunk Search

How do you create a Splunk query to get new inbound IP's?

arrangineni
Path Finder

I am trying to get a list of new inbound IPs/hosts, which would compare to the old data of the previous month from a firewall checkpoint data source.

We are using Splunk_TA_opseclea - loggrabber.sh for on-boarding the data into Splunk. Can anyone help with the query that collects can bring out the report?

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...