Splunk Search

Linux Equivalent commmand in Splunk

Samiksha1008
Observer

I have below command in Linux -

grep "login?" access.log access.log.1 | grep https | cut -d, -f3 | sed 's/"wafip"://g' | sort -n | uniq -c | sort -nr | head -100

 

I need to find out equivalent Splunk command. 
I know the index and host. 

Can somebody please help me with this?

 

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

can you tell what you want to get from log and give examples with log and output of your onliner?

r. Ismo

0 Karma

Samiksha1008
Observer

Hi @isoutamo 

I want to fetch ip addresses from the logs and display on the splunk. 

Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Source and destination addresses or any other what there could be?

Can you give example of your access.log (anonymised)?

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...