Post cover image
The SSH source IP was visible inside the raw events, but my search could not yet group the events using src_ip.

September 4, 2026

The IP Address Was in My Splunk Logs. Splunk Still Couldn’t Use It.

In Article 2, I got Linux authentication telemetry into Splunk.

By William | SOC and Detection Engineering

3 min read