I have a list of about 200 userids for which I want to fetch the client ip address (from which they logged on )- is there a query for that ?
If you have a lookup table in CSV format you are able to add it to Splunk and use the lookup command to match users and output their IP address.
Your lookup-table should look like the following. (example)
Use this documentation to upload and add that lookup table to splunk:
You can then use the lookup command to get the required data.
Example-Statement: index=example username=* | lookup nameofmylookuptable user AS username OUTPUT ip
The example assumes that the user in your eventdata is stored in a field called "username"
index=example username=* | lookup nameofmylookuptable user AS username OUTPUT ip