Splunk Search

Search again based on IP

wczimmerman
Engager

Inexperienced with Splunk:

I have a single log server that in collecting all data into one source (file) which Splunk is then digesting (DHCP, etc). I need to search for a particular field in that data (we will call it "cats") and if it matches, use the source_ip field from the matching results to then search for the matching DHCP request line in the same source. In other words, I need to find when a user obtained a DHCP address if they have a matching "cats" field.

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi wczimmerman,

like @lguinn said, logs would help.
Nevertheless take a lock at this superb blog entry by Splunk hero @kbains about using streamstats on some DHCP logs. This will show you a nice way to start looking for cats and DHCP leases....

cheers, MuS

0 Karma

lguinn2
Legend

It will help a lot if you can give a line or two of each type of data (obfuscated) - showing the "cats" field and the DHCP request line.

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...