Splunk Search

Search again based on IP

wczimmerman
Engager

Inexperienced with Splunk:

I have a single log server that in collecting all data into one source (file) which Splunk is then digesting (DHCP, etc). I need to search for a particular field in that data (we will call it "cats") and if it matches, use the source_ip field from the matching results to then search for the matching DHCP request line in the same source. In other words, I need to find when a user obtained a DHCP address if they have a matching "cats" field.

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi wczimmerman,

like @lguinn said, logs would help.
Nevertheless take a lock at this superb blog entry by Splunk hero @kbains about using streamstats on some DHCP logs. This will show you a nice way to start looking for cats and DHCP leases....

cheers, MuS

0 Karma

lguinn2
Legend

It will help a lot if you can give a line or two of each type of data (obfuscated) - showing the "cats" field and the DHCP request line.

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...