Splunk Search

How to search use stats count filter two fields?

longmen
Path Finder

Hi All,

I am doing a search for src_ip and DestAdd in a database within a 1 minute time frame. I need to look for src_ip which value that is not greater than 1 and DestAdd that is not greater than 5. Here is the description of the problem: when any of these with the same source IP more than 1 time, across more than 5 destination IP within 1 minutes. I wonder if my query correct. Can anyone advise? Thanks 

 

|bin span=1m _time |stats count(src_ip) as src_ip, count(DestAddress) as DestAddress by _time  |where (src_ip > 1 and DestAddress>5)

 

Labels (2)
0 Karma
1 Solution

yuanliu
SplunkTrust
SplunkTrust

One thing is not completely clear in your description.  Any src_ip that makes contact with "more than 5 destination IP within 1 minutes" must have appeared "more than 1 time" during the same minute.  Is there some additional constraint?

If there is no additional condition, you can use this search

| bin span=1m _time
| stats dc(DestAddress) as unique_dest by src_ip _time
| where unique_dest > 5

This is assuming that src_ip and DestAddress are present in the same event.  The question doesn't seem to make sense if an event only contains src_ip or DestAddress but not both, unless there is some other way to link src_ip and DestAddress.  If that is the case, you will need to analyze that link.

 

View solution in original post

yuanliu
SplunkTrust
SplunkTrust

One thing is not completely clear in your description.  Any src_ip that makes contact with "more than 5 destination IP within 1 minutes" must have appeared "more than 1 time" during the same minute.  Is there some additional constraint?

If there is no additional condition, you can use this search

| bin span=1m _time
| stats dc(DestAddress) as unique_dest by src_ip _time
| where unique_dest > 5

This is assuming that src_ip and DestAddress are present in the same event.  The question doesn't seem to make sense if an event only contains src_ip or DestAddress but not both, unless there is some other way to link src_ip and DestAddress.  If that is the case, you will need to analyze that link.

 

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...