You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Splunk技术需求:查找仅在指定日期后出现的新IP地址

在Splunk中找出2022年10月1日后首次登录的IP地址

这里有两种可靠的方法实现你的需求,你可以根据自己的日志结构选择:

方法1:统计IP首次出现时间

这种方法直接计算每个IP的首次登录时间,再筛选符合时间范围的结果:

# 替换成你的日志索引、源类型和登录事件筛选条件
index=your_log_index sourcetype=your_sourcetype action=login
| stats earliest(_time) as first_login_timestamp by src_ip
# 将日期字符串转为时间戳,筛选首次登录在2022-10-01之后的IP
| where first_login_timestamp > strptime("2022-10-01", "%Y-%m-%d")
# 把时间戳转为可读格式
| eval first_login_time=strftime(first_login_timestamp, "%Y-%m-%d %H:%M:%S")
# 展示结果列
| table src_ip first_login_time

关键部分说明:

  • earliest(_time):获取每个IP在日志中第一次出现的时间戳
  • strptime("2022-10-01", "%Y-%m-%d"):把指定日期转为Splunk可识别的时间戳
  • 请根据实际日志调整src_ip(可能是client_ip、ip_address等)、action=login这类登录事件的筛选条件。

方法2:排除历史出现过的IP

这种方法先提取2022-10-01之后的登录IP,再排除掉在此之前已经出现过的IP:

# 先获取2022-10-01之后的登录IP
index=your_log_index sourcetype=your_sourcetype action=login earliest=2022-10-01
| stats count by src_ip
# 子查询获取2022-09-30及之前出现过的IP,排除这些IP
| search NOT [ search index=your_log_index sourcetype=your_sourcetype action=login latest=2022-09-30 | fields src_ip ]
| table src_ip

适用场景:

如果你的日志量极大,这种方法可能更高效——因为它只需要分别处理两个时间范围的数据集,避免全量统计所有IP的首次时间。

内容的提问来源于stack exchange,提问作者Bob Bobson The Third Esq.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 10:35:35