<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Extracting hostname from event and then checking presence of computer account in ActiveDirectory using extracted text in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Extracting-hostname-from-event-and-then-checking-presence-of/m-p/160597#M32557</link>
    <description>&lt;P&gt;Many thanks, I messed up when marking answers so you should both get the nod for answering my question&lt;/P&gt;</description>
    <pubDate>Mon, 16 Dec 2013 13:08:02 GMT</pubDate>
    <dc:creator>dmcinnis</dc:creator>
    <dc:date>2013-12-16T13:08:02Z</dc:date>
    <item>
      <title>Extracting hostname from event and then checking presence of computer account in ActiveDirectory using extracted text</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Extracting-hostname-from-event-and-then-checking-presence-of/m-p/160593#M32553</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;

&lt;P&gt;I have a question regarding looking up a extracted/generated field from splunk against active directory at search time.&lt;BR /&gt;
The objective is as follows&lt;BR /&gt;
1. Extract hostname from DHCP log&lt;BR /&gt;
2. Check if hostname is present as a Computer object in AD&lt;BR /&gt;
3. If not present, return hostname as a result&lt;/P&gt;

&lt;P&gt;Do I have to extract all AD computer account objects and then put them in a CSV file to do a lookup against, or is it possible to compare the extracted hostnames against AD directly at search time using something like inline ldapsearch?&lt;/P&gt;

&lt;P&gt;Any help would be greatly appreciated, I hope my search fu did not miss an answer to this kind of question already.&lt;/P&gt;

&lt;P&gt;Many thanks&lt;BR /&gt;
David.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Nov 2013 14:02:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Extracting-hostname-from-event-and-then-checking-presence-of/m-p/160593#M32553</guid>
      <dc:creator>dmcinnis</dc:creator>
      <dc:date>2013-11-29T14:02:39Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting hostname from event and then checking presence of computer account in ActiveDirectory using extracted text</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Extracting-hostname-from-event-and-then-checking-presence-of/m-p/160594#M32554</link>
      <description>&lt;P&gt;you can use 'ldapfilter' command to query against LDAP in the search.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Nov 2013 16:08:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Extracting-hostname-from-event-and-then-checking-presence-of/m-p/160594#M32554</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2013-11-29T16:08:01Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting hostname from event and then checking presence of computer account in ActiveDirectory using extracted text</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Extracting-hostname-from-event-and-then-checking-presence-of/m-p/160595#M32555</link>
      <description>&lt;P&gt;use a subsearch result to populate the search condition from the main search.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;&amp;lt;main_search_conditions&amp;gt;  [ search &amp;lt;subsearch_on_ldap&amp;gt; | dedup host | table host ]&lt;BR /&gt;
|  &amp;lt;end_of_my_mainsearch_processing&amp;gt;&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;The subsearch will return something in the format (host=A OR host=B OR host=C ...)&lt;BR /&gt;
The timerange will be the same for both searches. You can specify manually in the search terms if different ranges are needed.&lt;/P&gt;

&lt;P&gt;see &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0/Search/Usesubsearchtocorrelateevents"&gt;http://docs.splunk.com/Documentation/Splunk/6.0/Search/Usesubsearchtocorrelateevents&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Nov 2013 17:45:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Extracting-hostname-from-event-and-then-checking-presence-of/m-p/160595#M32555</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2013-11-29T17:45:10Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting hostname from event and then checking presence of computer account in ActiveDirectory using extracted text</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Extracting-hostname-from-event-and-then-checking-presence-of/m-p/160596#M32556</link>
      <description>&lt;P&gt;It certainly is possible to perform a dynamic (scripted) lookup against any external source (such as Active Directory) rather than keeping the file up to date, or using a subsearch. &lt;/P&gt;

&lt;P&gt;The subsearch as answered by &lt;CODE&gt;yannK&lt;/CODE&gt; does solve your problem, provided you use the &lt;CODE&gt;ldapsearch&lt;/CODE&gt; search command that is provided in the Splunk Support for AD app &lt;A href="http://apps.splunk.com/app/1151/#"&gt;http://apps.splunk.com/app/1151/#&lt;/A&gt; It does have some limitations though.&lt;/P&gt;

&lt;P&gt;If you did want a lookup, you would either keep the AD CSV file up-to-date, or you would build a dynamic lookup. Unfortunately the Splunk AD app doesn't include such a program. You can find out how to structure such a lookup program here: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0/Knowledge/Addfieldsfromexternaldatasources#Set_up_a_fields_lookup_based_on_an_external_command_or_script"&gt;http://docs.splunk.com/Documentation/Splunk/6.0/Knowledge/Addfieldsfromexternaldatasources#Set_up_a_fields_lookup_based_on_an_external_command_or_script&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Nov 2013 20:36:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Extracting-hostname-from-event-and-then-checking-presence-of/m-p/160596#M32556</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2013-11-29T20:36:05Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting hostname from event and then checking presence of computer account in ActiveDirectory using extracted text</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Extracting-hostname-from-event-and-then-checking-presence-of/m-p/160597#M32557</link>
      <description>&lt;P&gt;Many thanks, I messed up when marking answers so you should both get the nod for answering my question&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2013 13:08:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Extracting-hostname-from-event-and-then-checking-presence-of/m-p/160597#M32557</guid>
      <dc:creator>dmcinnis</dc:creator>
      <dc:date>2013-12-16T13:08:02Z</dc:date>
    </item>
  </channel>
</rss>

