Splunk Search

Match IP network source

pfries54
New Member

I want to add data of a network, for example 192.168.0.0/24.
But when i select TCP/UDP, and i add 192.168.0.* on "Accept connection of" i don't receive log of my network.
But it work when i just indicate UDP port.

It's a problem with my regex ?

0 Karma
1 Solution

nickhills
Ultra Champion

Splunk is not a network sniffer in itself.

Your option are:

  1. Configure Syslog to send data from each host on your network to a TCP/UDP port

    https://access.redhat.com/solutions/54363

  2. Install a Universal forwarder on each of your hosts

    http://docs.splunk.com/Documentation/Forwarder/7.0.1/Forwarder/HowtoforwarddatatoSplunkEnterprise

  3. Install and deploy Splunk Stream for network traffic

    https://splunkbase.splunk.com/app/1809/

  4. many others

If my comment helps, please give it a thumbs up!

View solution in original post

0 Karma

nickhills
Ultra Champion

Splunk is not a network sniffer in itself.

Your option are:

  1. Configure Syslog to send data from each host on your network to a TCP/UDP port

    https://access.redhat.com/solutions/54363

  2. Install a Universal forwarder on each of your hosts

    http://docs.splunk.com/Documentation/Forwarder/7.0.1/Forwarder/HowtoforwarddatatoSplunkEnterprise

  3. Install and deploy Splunk Stream for network traffic

    https://splunkbase.splunk.com/app/1809/

  4. many others

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...