<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What is the best way to  build searches and alerting in a Hyper-V environment in which VMs pull MAC address ? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-is-the-best-way-to-build-searches-and-alerting-in-a-Hyper-V/m-p/642572#M11507</link>
    <description>&lt;P&gt;What is the best way to deal with building searches and alerting in a Hyper-V environment in which VMs pull MAC address from a pool controlled by the cluster nodes?&amp;nbsp; Is setting all of my VMs to use static MAC addresses best practice (this is a large undertaking and would require maintenance) or is there a better way to do this?&amp;nbsp; Should I rely on another variable to track these assets?&lt;/P&gt;</description>
    <pubDate>Tue, 09 May 2023 06:07:44 GMT</pubDate>
    <dc:creator>gg74</dc:creator>
    <dc:date>2023-05-09T06:07:44Z</dc:date>
    <item>
      <title>What is the best way to  build searches and alerting in a Hyper-V environment in which VMs pull MAC address ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-is-the-best-way-to-build-searches-and-alerting-in-a-Hyper-V/m-p/642572#M11507</link>
      <description>&lt;P&gt;What is the best way to deal with building searches and alerting in a Hyper-V environment in which VMs pull MAC address from a pool controlled by the cluster nodes?&amp;nbsp; Is setting all of my VMs to use static MAC addresses best practice (this is a large undertaking and would require maintenance) or is there a better way to do this?&amp;nbsp; Should I rely on another variable to track these assets?&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 06:07:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-is-the-best-way-to-build-searches-and-alerting-in-a-Hyper-V/m-p/642572#M11507</guid>
      <dc:creator>gg74</dc:creator>
      <dc:date>2023-05-09T06:07:44Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to  build searches and alerting in a Hyper-V environment in which VMs pull MAC address ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-is-the-best-way-to-build-searches-and-alerting-in-a-Hyper-V/m-p/642594#M11508</link>
      <description>&lt;P&gt;If you want a deterministic way to track assets, don't use a non-deterministic way of identifying the assets.&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 06:10:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-is-the-best-way-to-build-searches-and-alerting-in-a-Hyper-V/m-p/642594#M11508</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-05-09T06:10:02Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to  build searches and alerting in a Hyper-V environment in which VMs pull MAC address ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-is-the-best-way-to-build-searches-and-alerting-in-a-Hyper-V/m-p/642646#M11509</link>
      <description>&lt;P&gt;Is there a better variable to use than the MAC address?&amp;nbsp; Something that doesn't rely on manual intervention to set?&amp;nbsp; Is the GUID or device name the standard?&amp;nbsp; Just looking options I may not be aware of.&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 11:55:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-is-the-best-way-to-build-searches-and-alerting-in-a-Hyper-V/m-p/642646#M11509</guid>
      <dc:creator>gg74</dc:creator>
      <dc:date>2023-05-09T11:55:57Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to  build searches and alerting in a Hyper-V environment in which VMs pull MAC address ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-is-the-best-way-to-build-searches-and-alerting-in-a-Hyper-V/m-p/642648#M11510</link>
      <description>&lt;P&gt;It depends how your assets are set up - often a qualified host name is unique (enough) in your environment to distinguish between different hosts.&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 12:06:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-is-the-best-way-to-build-searches-and-alerting-in-a-Hyper-V/m-p/642648#M11510</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-05-09T12:06:55Z</dc:date>
    </item>
  </channel>
</rss>

