Splunk Search

How do you use the where clause in a cluster map?

everynameIwanti
Explorer

I'm trying to make a cluster map in Splunk by their IP address.

I grouped the IP by id number, and I want to only show the cluster which each an ID has more than 3 IP addressess.

I have the following code:

index="xxx"  id != "-"  | iplocation ip | geostats dc(ip) by id

And I tried to make a variable name for dc(ip) (like dc(ip) as ipCount) so that I can use it in the where clause (where ipCount > 3), but unfortunately geostats doesn't allow me to rename.

Does anybody know how or where to add a where clause or is there another way of making the map?

Thank you

0 Karma
1 Solution

adonio
Ultra Champion

without testing, maybe something along those lines:

 index="xxx" id != "-" 
| eventstats dc(ip) as unique_ips by id 
| where unique_ips > 3
| iplocation ip | geostats max(unique_ips)  by id

hope it helps

View solution in original post

0 Karma

adonio
Ultra Champion

without testing, maybe something along those lines:

 index="xxx" id != "-" 
| eventstats dc(ip) as unique_ips by id 
| where unique_ips > 3
| iplocation ip | geostats max(unique_ips)  by id

hope it helps

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...