- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to search traffic log with multiple source ip addresses (more than 100 ip addresses)?
Is there any way that i can search for more than 100 ip addresses? What i do the searching in analyzer as below:
srcip=1.1.1.1 or srcip=2.2.2.2 or srcip=3.3.3.3
And this way will allow maximum 30 ip addresses to key into search field, so is there any way to search more 100 ip addresses at once?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I know there is enable column filter option, once you enabled it then you can filter only 1 ip address, i need more than that...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
You can use wildcard i.e, see attached screenshot
regards
/ Abel
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
or even no range of address
vd=soc01 srcip=10.1.1.20-10.1.1.26
PCNSE
NSE
StrongSwan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Both suggestions above (Wild card and the IP range) are better that what I would have done :), but I would add that you can search by CIDR notation as well:
srcip=10.1.1.0/24
for example.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
James.F.Holmes wrote:Both suggestions above (Wild card and the IP range) are better that what I would have done :), but I would add that you can search by CIDR notation as well:
srcip=10.1.1.0/24
for example.
my source ip addresses are not under the same range...so i can't use wildcard or CIDR...all ip address is unique...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
It's easier to run a report filtered by the source IP addresses using comma separator.
You can add multiple IP addresses to the same srcip filter, however I'm not sure how many IP addresses the filter will accept. If the filter accepts lets say 50 IP addresses then add two srcip filters and split the IP list between them.
Regards,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
awasfi wrote:Hello,
It's easier to run a report filtered by the source IP addresses using comma separator.
You can add multiple IP addresses to the same srcip filter, however I'm not sure how many IP addresses the filter will accept. If the filter accepts lets say 50 IP addresses then add two srcip filters and split the IP list between them.
Regards,
comma separator is not working if you are refer to this...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
I mean use one of the default report or your custom report to get the information you want by filtering the report itself by the source IP addresses (Advanced settings tab):
Regards,
