Splunk Search

How to search multiple dstIP traffic most efficiently

SimonM
New Member

Its a basic request however has been causing me grief:

Easiest / most efficient way to find Destination IP (dstip) for multiple IP list:

I regularly am supplied with a list of IP  (10-20) for confirmation

Need to stop using ;

OR ""  OR "" OR ""

 

Like to use  simple lookup for multiple dstIP if possible - copy and paste IP scenario

 

index=? if dstip =    

1.2.3.4

2.3.4.5

3.4.5.6

4.5.6.7

| table hostname, hostip

 

Yes I'm learning but I super appreciate any help with this easy one > will save me hours

Labels (1)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

I am confused.  Is this a simple exercise of list operator IN in search? (Search: Comparison expression options)

index=? dstip IN (
1.2.3.4,
2.3.4.5,
3.4.5.6,
4.5.6.7)
| table hostname, hostip

 

0 Karma
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...