what are the query to use by lookup an IP information like country only for source_IP and destination_IP in your search?
ex:
index =xxxx action=allowed severity=* src-ip=* dest-ip=* |table host, signature,src-ip, dest-ip, action, severity
Q/ in the above query, what are the query i can use to fetch src-ip country name and dest-ip country name
Thank you in advance!
You want the iplocation
command (https://docs.splunk.com/Documentation/Splunk/8.0.3/SearchReference/Iplocation).
index =xxxx action=allowed severity= src_ip= dest_ip=*
| iplookup src_ip
| rename country as src_country
| iplookup dest_ip
| rename country as dest_country
| table host, signature,src_ip, src_country,dest_ip, dest_country, action, severity