Splunk Search

Splunk query to find IP attack in Geo Map


 index=graphsecurityalert having information's about all attacks in "title" field

index=zscaler having information's about all IP & location  but it don't have logs about attacks.

Now i want query to find in geo map with IP and title of the attack.

i tried index=graphsecutity OR index=zscaler title=* | iplocation src_ip | geostats count by userStates{}.logonLocation  but i am unable to get results.


Please help me with query to find IP attacks in geo map

@soutamo @saravanan90 @thambisetty @ITWhisperer @gcusello @bowesmana   @to4kawa 

Labels (2)
0 Karma



Can you provide sanitized sample events? I'm assuming you want to join Microsoft Graph Security API Add-On for Splunk events with Zscaler Technical Add-On for Splunk events.

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!