Splunk Search

How to search multiple dstIP traffic most efficiently

SimonM
New Member

Its a basic request however has been causing me grief:

Easiest / most efficient way to find Destination IP (dstip) for multiple IP list:

I regularly am supplied with a list of IP  (10-20) for confirmation

Need to stop using ;

OR ""  OR "" OR ""

 

Like to use  simple lookup for multiple dstIP if possible - copy and paste IP scenario

 

index=? if dstip =    

1.2.3.4

2.3.4.5

3.4.5.6

4.5.6.7

| table hostname, hostip

 

Yes I'm learning but I super appreciate any help with this easy one > will save me hours

Labels (1)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

I am confused.  Is this a simple exercise of list operator IN in search? (Search: Comparison expression options)

index=? dstip IN (
1.2.3.4,
2.3.4.5,
3.4.5.6,
4.5.6.7)
| table hostname, hostip

 

0 Karma
Get Updates on the Splunk Community!

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

Getting Started with AIOps: Event Correlation Basics and Alert Storm Detection in ...

Getting Started with AIOps:Event Correlation Basics and Alert Storm Detection in Splunk IT Service ...

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...