Splunk Search

How to search list of IPs to check if they're sending data to Splunk?

Mr_Data_2018
New Member

I have a list of IPs and want to check if they are sending data to Splunk but using a single query.
The devices in this list need troubleshooting.
Is there some query I could run referencing this list to get an output of stats or something similar?
Any guidance, please?

 

Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Store you ips in a lookup and extend your search to filter using the stored ips

<your search> [| inputlookup iplist.csv | fields ip | format]
0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...