You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Splunk查询问题:如何统计10分钟内同一源IP超50次连接(检测DDoS)

Splunk DDoS检测查询修正方案

原查询的问题分析

你的查询存在3个关键错误,导致无法生成预期的表格视图:

  1. 语法错误:stats count by src_ip AS ip_count写法不正确,AS别名需放在统计字段前,正确格式是stats count AS ip_count by src_ip
  2. 字段丢失:使用timechart span=10m count时未指定by src_ip,会导致src_ip字段被丢弃,后续table src_ip无法找到该字段
  3. 逻辑顺序错误:先按src_ip统计再做时间聚合,不符合“10分钟窗口内同一源IP连接数”的需求逻辑

修正后的查询语句

index="*" srccountry!="Reserved"
| bin _time span=10m  # 将时间戳按10分钟窗口分组
| stats count AS ip_count by _time, src_ip  # 统计每个时间窗口内各源IP的连接次数
| where ip_count > 50  # 过滤出连接次数超过50次的记录
| table _time, src_ip, ip_count  # 展示时间窗口、源IP、连接次数的表格

可选优化:用timechart实现(兼顾趋势可视化)

如果需要同时查看时间趋势和表格数据,可使用以下写法:

index="*" srccountry!="Reserved"
| timechart span=10m count AS ip_count by src_ip useother=f usenull=f
| untable _time, src_ip, ip_count
| where ip_count > 50
| table _time, src_ip, ip_count

额外建议

如果你的数据中有入站连接标记字段(比如direction="inbound"),建议加入过滤条件,避免统计出站连接,让检测更精准:

index="*" srccountry!="Reserved" direction="inbound"
| bin _time span=10m
| stats count AS ip_count by _time, src_ip
| where ip_count > 50
| table _time, src_ip, ip_count

内容的提问来源于stack exchange,提问作者Bob Bobson The Third Esq.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 09:05:08