Splunk Search

How do you use the where clause in a cluster map?

everynameIwanti
Explorer

I'm trying to make a cluster map in Splunk by their IP address.

I grouped the IP by id number, and I want to only show the cluster which each an ID has more than 3 IP addressess.

I have the following code:

index="xxx"  id != "-"  | iplocation ip | geostats dc(ip) by id

And I tried to make a variable name for dc(ip) (like dc(ip) as ipCount) so that I can use it in the where clause (where ipCount > 3), but unfortunately geostats doesn't allow me to rename.

Does anybody know how or where to add a where clause or is there another way of making the map?

Thank you

0 Karma
1 Solution

adonio
Ultra Champion

without testing, maybe something along those lines:

 index="xxx" id != "-" 
| eventstats dc(ip) as unique_ips by id 
| where unique_ips > 3
| iplocation ip | geostats max(unique_ips)  by id

hope it helps

View solution in original post

0 Karma

adonio
Ultra Champion

without testing, maybe something along those lines:

 index="xxx" id != "-" 
| eventstats dc(ip) as unique_ips by id 
| where unique_ips > 3
| iplocation ip | geostats max(unique_ips)  by id

hope it helps

View solution in original post

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!