Splunk Search

Search again based on IP

wczimmerman
Engager

Inexperienced with Splunk:

I have a single log server that in collecting all data into one source (file) which Splunk is then digesting (DHCP, etc). I need to search for a particular field in that data (we will call it "cats") and if it matches, use the source_ip field from the matching results to then search for the matching DHCP request line in the same source. In other words, I need to find when a user obtained a DHCP address if they have a matching "cats" field.

0 Karma

MuS
Legend

Hi wczimmerman,

like @lguinn said, logs would help.
Nevertheless take a lock at this superb blog entry by Splunk hero @kbains about using streamstats on some DHCP logs. This will show you a nice way to start looking for cats and DHCP leases....

cheers, MuS

0 Karma

lguinn2
Legend

It will help a lot if you can give a line or two of each type of data (obfuscated) - showing the "cats" field and the DHCP request line.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...