Splunk Search

IP address search by a project ID

the_gambler
New Member

I have certain project IDs I'm trying to get a list of IP addresses from.

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @the_gambler ,

as @ITWhisperer said, you didn't share suffieicnt information to help you.

I can suppose that you have a field called Project_ID and a field called IP_Address, in this case, try something like this:

index=your_index
| stats values(IP_Address) AS IP_Address BY Project_ID

Ciao.

Giuseppe

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You haven't provided sufficient information for us to be able to help you - what ip addresses? how do they relate to the project ids? Can you share some anonymised examples of the events you are dealing with?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...