Splunk Search

Is there a Splunk query to find the client ip addresses for a list of usernames?

New Member

I have a list of about 200 userids for which I want to fetch the client ip address (from which they logged on )- is there a query for that ?

Tags (3)
0 Karma


Hi tksre,

If you have a lookup table in CSV format you are able to add it to Splunk and use the lookup command to match users and output their IP address.

Your lookup-table should look like the following. (example)

user, ip

Use this documentation to upload and add that lookup table to splunk:

You can then use the lookup command to get the required data.

Example-Statement: index=example username=* | lookup nameofmylookuptable user AS username OUTPUT ip
The example assumes that the user in your eventdata is stored in a field called "username"

Further documentation:

0 Karma