Splunk Search

subsearch by ip and then host

mcbradford
Contributor

I am building a dashboard based on all activity related to an IP. I have one source that generates events, but does not always include the IP. The events that do have an IP always have the host name. From one search, I want to search by IP, but also associate the IP to a host name and then search again with the host name and display all events.

Tags (1)
0 Karma

gpullis
Communicator

You're looking for something like this?

source="mySourceType" [search source="mySourceType" myIPAddressField=192.168.53.105 | fields host]
0 Karma

mcbradford
Contributor

that worked - thanks!

Get Updates on the Splunk Community!

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...