Splunk Search

Search only spesific country

gijoesplunk
New Member

Hi I'm new in splunk.I have a firewall that send the log to splunk , and one of the information provide in the firewall log is country. And i want to search in splunk and came out the result for only all eastern europe country or all africa country without having to list one by one all the country, is it possible to do that?

Tags (1)
0 Karma

sundareshr
Legend

You will have to create a lookup table that has the mapping between country and continent/sub continent. You can then create a automatic lookup to add continent info to your events and use that to search.

http://docs.splunk.com/Documentation/Splunk/6.4.3/SearchReference/Lookup

OR

You can create/maintain tags

https://docs.splunk.com/Documentation/Splunk/6.4.3/Knowledge/Abouttagsandaliases

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...