Splunk技术需求:查找仅在指定日期后出现的新IP地址
在Splunk中找出2022年10月1日后首次登录的IP地址
这里有两种可靠的方法实现你的需求,你可以根据自己的日志结构选择:
方法1:统计IP首次出现时间
这种方法直接计算每个IP的首次登录时间,再筛选符合时间范围的结果:
# 替换成你的日志索引、源类型和登录事件筛选条件 index=your_log_index sourcetype=your_sourcetype action=login | stats earliest(_time) as first_login_timestamp by src_ip # 将日期字符串转为时间戳,筛选首次登录在2022-10-01之后的IP | where first_login_timestamp > strptime("2022-10-01", "%Y-%m-%d") # 把时间戳转为可读格式 | eval first_login_time=strftime(first_login_timestamp, "%Y-%m-%d %H:%M:%S") # 展示结果列 | table src_ip first_login_time
关键部分说明:
earliest(_time):获取每个IP在日志中第一次出现的时间戳strptime("2022-10-01", "%Y-%m-%d"):把指定日期转为Splunk可识别的时间戳- 请根据实际日志调整
src_ip(可能是client_ip、ip_address等)、action=login这类登录事件的筛选条件。
方法2:排除历史出现过的IP
这种方法先提取2022-10-01之后的登录IP,再排除掉在此之前已经出现过的IP:
# 先获取2022-10-01之后的登录IP index=your_log_index sourcetype=your_sourcetype action=login earliest=2022-10-01 | stats count by src_ip # 子查询获取2022-09-30及之前出现过的IP,排除这些IP | search NOT [ search index=your_log_index sourcetype=your_sourcetype action=login latest=2022-09-30 | fields src_ip ] | table src_ip
适用场景:
如果你的日志量极大,这种方法可能更高效——因为它只需要分别处理两个时间范围的数据集,避免全量统计所有IP的首次时间。
内容的提问来源于stack exchange,提问作者Bob Bobson The Third Esq.
相关产品推荐
相关产品推荐

