How can I find all traffic logged from 172.18.128 using Splunk search? This much be the simplest thing. But I can't get the dern thing to return a thing!
amigan_99
amigan_99
So here are examples of what started working for me:

index="vmwarensx" AND "DROP" AND "TCP"

(index="pan_logs" OR index="juniper_logs" OR index="aws_vpc_flow_logs" OR index="vmwarensx") AND ""
btan
Probably not due to (only) search string ... and there are other factors ...

a) Maybe can do a quick try src="172.18.128.*" OR dst="172.18.128.*" or even some IP (w/o wildcard) that you know will hit. This is just to confirm it is not a empty scan count (number of events that are scanned or read off disk)

b) Check Settings -> Indexes to make sure there's events in the indexes. And check index=_internal log_level=ERROR to see if there's a problem. Was know that search.log may be deleted and added it again with a new index instead of the default index. The latter may cause such issue at time (one instance here)

c)  Free version (especially after the trial expires) of Splunk has an indexing limit of 500 Mb per day. If you index above your licensing limit more than 3 times in a 30 day window on the free version, the search functionality becomes disabled until you either get an unlock key, input a new license or one of the violations rolls past the 30 day window and your total licensing violations fall to 3 or less.
btan
Thanks for sharing. So does it still work out for the wildcard scenarios as mentioned in question?
amigan_99
No - and I just tried again say 172.2.163.*. Specifying the index seems important and quotes around the search term. It's super fast so that's a big plus.
btan
If another address such as 10.32.14.* is used which it should have a hit but not working then it seems there is issue this s/w. It can be due to other factor as I shared earlier.
amigan_99
Thanks much btan for helping me with yet another issue.
