Splunk Search

How to search for IP addresses from a .txt file to see if any of them have appeared in Splunk before?

simeidem
New Member

Hi,

I have a .txt-file with line separated IP addresses, and I want to know if any of those have appeared in Splunk before.

I could manually enter all the IP addresses in search with "OR" between, but that would literally take weeks..

What to do?

Thanks,
Simon

Tags (3)
0 Karma

jeffland
SplunkTrust
SplunkTrust

You could either index the file with splunk and reference it from there, or you could use a lookup. I would recommend you use a lookup, that way you can use the content of the file dynamically (i.e. update the info in it).

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...