Splunk Search

Search again based on IP

wczimmerman
Engager

Inexperienced with Splunk:

I have a single log server that in collecting all data into one source (file) which Splunk is then digesting (DHCP, etc). I need to search for a particular field in that data (we will call it "cats") and if it matches, use the source_ip field from the matching results to then search for the matching DHCP request line in the same source. In other words, I need to find when a user obtained a DHCP address if they have a matching "cats" field.

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi wczimmerman,

like @lguinn said, logs would help.
Nevertheless take a lock at this superb blog entry by Splunk hero @kbains about using streamstats on some DHCP logs. This will show you a nice way to start looking for cats and DHCP leases....

cheers, MuS

0 Karma

lguinn2
Legend

It will help a lot if you can give a line or two of each type of data (obfuscated) - showing the "cats" field and the DHCP request line.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...