Splunk Search

Is there a way to get a True or False match on source IP with Tor exit node list in a timechart?

New Member

I would like to know if there is a way to get true/false match on source IP to see tor sourced traffic over time in a time chart.

0 Karma

Path Finder

You can place the TOR exit node list into a CSV then at search time use an inputlookup like so:

index=firewall [|inputlookup torexitnodes.csv | fields exitnodeip ] 

Because Tor exit nodes change constantly you will probably need to have this CSV automatically updated by a script.

0 Karma



Can you please suggest from where can we download the latest tor exit nodes IP details. Thanks in advance

0 Karma


If you haven't found a good place for tor exit nodes, http://iplists.firehol.org/ is a great resource.

Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes and swag!