Splunk Search

How to use a CSV file of IP addresses and countries to set up an alert if an international IP is contacted on our network?

bcyates
Communicator

Our Splunk admin has recently moved on to a new position here so I am trying to fill the void until a replacement is brought on board. My admin experience with Splunk is limited (only what he turned over to me before he left.)

My goal here is to be able to setup an alert anytime that an international IP is contacted on our network. Whether it be a local user accessing a site that has an international IP or a malicious email attachment redirecting to an international IP.

I have a list of IPs and which Country they predominantly belong to on a CSV file. Has anyone done this and if so, what is the best way to go about doing it?

0 Karma

gfreitas
Builder

Hi bcyates,

The easiest way to do so is to use the command iplocation. This command generate a field called Country that show the country of the IP address automatically. You can do:

your search | iplocation dstip | search NOT Country = "country"

Hope this helps.

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...