Splunk Search

Searching a 2nd index with a field extraction using rex

dhabbal
Explorer

I have a index=weblogs where I filter results and then REX extract an IP address to a new field called RemoteIP.

I want to then search our firewall logs on index=firewall for that newly extracted field RemoteIP.

I have been playing around with sub searches and joins but not getting far. 

 

Labels (3)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
index=firewall [ search index=weblogs | rex "extract remote ip" | dedup remoteIP | rename remoteIP as ipFieldInFirewall | fields ipFieldInFirewall ]

View solution in original post

dhabbal
Explorer

Believe it or not I figured it out shortly after you posted this solution. Thank you!


Can I ask how to now use join? I want to bring in fields from index=weblogs into the outter search. 

 

The common field would be src_ip. 

Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
index=firewall 
| join ipFieldInFirewall [ search index=weblogs | rex "extract remote ip" | dedup remoteIP | rename remoteIP as ipFieldInFirewall | fields ipFieldInFirewall plus other fields ]

dhabbal
Explorer

Thanks for this, I tried this join syntax earlier but the search was very slow and wasn't able to be completed.

Firewall logs are huge but I thought the subsearch runs first that feeds the join cmd, in my mind it should run fairly quickly but it's taking very long. 

Any ideas how to make the search more performative?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
index=firewall [ search index=weblogs | rex "extract remote ip" | dedup remoteIP | rename remoteIP as ipFieldInFirewall | fields ipFieldInFirewall ]
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...