You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Splunk关联两个搜索无结果:排查登录IP匹配IoC的问题

排查与解决步骤

1. 先验证子查询是否有数据

首先单独运行IoC表的查询,确认是否存在有效IP指标:

index="threatstream_summary" sourcetype="stash" 
| table event.indicator

如果该查询返回空,说明IoC表本身无数据,需先排查索引、sourcetype配置是否正确,或调整时间范围覆盖有数据的时段。

2. 检查主查询的IP字段有效性

运行登录记录的基础查询,确认src_ip字段是否存在且有有效IP值:

"o365_management_activity" 
| table user, src_ip

若src_ip列是空值,或实际IP字段名并非src_ip(比如可能是source_ip、client_ip),可通过| fields *查看所有字段,定位正确的登录IP字段。

3. 核对IP格式是否匹配

无结果常因两边IP格式不一致导致:

  • 主查询src_ip可能带端口(如192.168.1.1:12345),而IoC表event.indicator是纯IP
  • 存在多余空格、特殊字符

针对带端口的情况,可在主查询中提取纯IP:

"o365_management_activity" Operation=UserLoggedIn
| rex field=src_ip "^(?P<clean_ip>\d+\.\d+\.\d+\.\d+)"
| table user, clean_ip

再用提取后的clean_ip与IoC的event.indicator匹配。

4. 调整Join语法与逻辑

默认join为内连接,需两边有匹配值才返回结果。可调整字段匹配逻辑,避免重命名带来的混淆:

"o365_management_activity" Operation=UserLoggedIn
| table user, src_ip
| join type=inner src_ip [
  search index="threatstream_summary" sourcetype="stash" 
  | rename event.indicator AS src_ip 
  | fields src_ip
]
| table user, src_ip

直接将IoC字段重命名为src_ip,与主查询字段名保持一致,降低出错概率。

5. 改用Lookup(更高效的IoC匹配方式)

Splunk中lookup比join更适合处理IoC匹配场景,尤其数据量较大时:

步骤1:生成临时Lookup表

index="threatstream_summary" sourcetype="stash" 
| dedup event.indicator
| outputlookup temp_ioc.csv

步骤2:用Lookup匹配登录记录

"o365_management_activity" Operation=UserLoggedIn
| table user, src_ip
| lookup temp_ioc.csv event.indicator AS src_ip
| where isnotnull(event.indicator)
| table user, src_ip

where isnotnull(event.indicator)会过滤未匹配IoC的记录,仅保留命中结果。

6. 确认时间范围一致

Splunk默认查询最近24小时,需确保登录记录与IoC记录的时间范围有重叠,比如IoC是一周前导入的,需将查询时间范围调整至过去7天。

内容的提问来源于stack exchange,提问作者Antonino Ciancia

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 23:32:53