Splunk Search

How to get count of c-ip from IIS logs indexed by splunk

ajaykulkarni
Engager

Hi All,

I am using Microsoft's Log Parser tool with which I can query my IIS logs.
Now I have a query to select different client ips and the count like,

select c-ip, count(c-ip)
FROM
File Name
group by c-ip

Same thing I need to try with splunk search, but I can't. 😞

Please help.

Tags (3)
0 Karma
1 Solution

Ayn
Legend

Do you have the c_ip field or similar extracted in Splunk? Where are you encountering problems?

View solution in original post

Ayn
Legend

Do you have the c_ip field or similar extracted in Splunk? Where are you encountering problems?

ajaykulkarni
Engager

I am extremely sorry, its my mistake.
In IIS logs we have c-ip and splunk has provided c_ip.
Solved the problem.
Thanks @Ayn.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...