<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Longitude in DA-ESS-ThreatIntelligence is named as 'long' but the base search is 'lon' in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Longitude-in-DA-ESS-ThreatIntelligence-is-named-as-long-but-the/m-p/422487#M5281</link>
    <description>&lt;P&gt;The following Bug had been logged with Product Management to clarify whether it was a Bug.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;SOLNESS-19368&lt;/STRONG&gt;   iplocation has a field called 'lon' in Splunk and 'long' in Enterprise Security&lt;/P&gt;

&lt;P&gt;The response from Product Management (who confirmed it is not a Bug) is below:&lt;/P&gt;

&lt;P&gt;CIM uses "long", but Splunk Enterprise's geo-location search command outputs "lon".&lt;BR /&gt;
So the discrepancy itself is expected, we just missed the conditional eval component to align things properly.&lt;/P&gt;</description>
    <pubDate>Wed, 31 Jul 2019 14:09:21 GMT</pubDate>
    <dc:creator>christopherr_sp</dc:creator>
    <dc:date>2019-07-31T14:09:21Z</dc:date>
    <item>
      <title>Longitude in DA-ESS-ThreatIntelligence is named as 'long' but the base search is 'lon'</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Longitude-in-DA-ESS-ThreatIntelligence-is-named-as-long-but-the/m-p/422486#M5280</link>
      <description>&lt;P&gt;There is a BUG in the DA-ESS-ThreatIntelligence app. &lt;/P&gt;

&lt;P&gt;In the Datamodel under &lt;EM&gt;Threat Intelligence  &amp;gt; IP Intelligence&lt;/EM&gt; there is a field named “long” this field is supposed to hold the longitude of the IP address in the “ip” field.&lt;/P&gt;

&lt;P&gt;Given the base search the field should be called “lon” because that is the field that the  “iplocation” command outputs OR a rename should be done in the search to rename “lon” to “long”.&lt;/P&gt;

&lt;P&gt;The problem found in DA-ESS-ThreatIntelligence 4.5.0 and above (all versions including the latest).&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2019 14:07:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Longitude-in-DA-ESS-ThreatIntelligence-is-named-as-long-but-the/m-p/422486#M5280</guid>
      <dc:creator>christopherr_sp</dc:creator>
      <dc:date>2019-07-31T14:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: Longitude in DA-ESS-ThreatIntelligence is named as 'long' but the base search is 'lon'</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Longitude-in-DA-ESS-ThreatIntelligence-is-named-as-long-but-the/m-p/422487#M5281</link>
      <description>&lt;P&gt;The following Bug had been logged with Product Management to clarify whether it was a Bug.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;SOLNESS-19368&lt;/STRONG&gt;   iplocation has a field called 'lon' in Splunk and 'long' in Enterprise Security&lt;/P&gt;

&lt;P&gt;The response from Product Management (who confirmed it is not a Bug) is below:&lt;/P&gt;

&lt;P&gt;CIM uses "long", but Splunk Enterprise's geo-location search command outputs "lon".&lt;BR /&gt;
So the discrepancy itself is expected, we just missed the conditional eval component to align things properly.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2019 14:09:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Longitude-in-DA-ESS-ThreatIntelligence-is-named-as-long-but-the/m-p/422487#M5281</guid>
      <dc:creator>christopherr_sp</dc:creator>
      <dc:date>2019-07-31T14:09:21Z</dc:date>
    </item>
  </channel>
</rss>

