Splunk Search

Linux Equivalent commmand in Splunk

Samiksha1008
Observer

I have below command in Linux -

grep "login?" access.log access.log.1 | grep https | cut -d, -f3 | sed 's/"wafip"://g' | sort -n | uniq -c | sort -nr | head -100

 

I need to find out equivalent Splunk command. 
I know the index and host. 

Can somebody please help me with this?

 

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

can you tell what you want to get from log and give examples with log and output of your onliner?

r. Ismo

0 Karma

Samiksha1008
Observer

Hi @isoutamo 

I want to fetch ip addresses from the logs and display on the splunk. 

Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Source and destination addresses or any other what there could be?

Can you give example of your access.log (anonymised)?

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...