<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk CMDB Lookup in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-CMDB-Lookup/m-p/542789#M9766</link>
    <description>&lt;P&gt;We want to override the lookup File as per the below condition.&lt;BR /&gt;&lt;BR /&gt;If File not exist - we don't want to override the lookup file.&lt;BR /&gt;And IF File exist - We can proceed to override the lookup file .&lt;BR /&gt;&lt;BR /&gt;index=siem_test sourcetype="db:cmdb"&lt;BR /&gt;| timechart count by source&lt;BR /&gt;&lt;BR /&gt;IF CMDB part not lost don't override the output lookup and how do we can check the sourcetype is not reporting.&lt;BR /&gt;&lt;BR /&gt;Please suggest any condition which we can use in our search query to populate the result.&lt;/P&gt;</description>
    <pubDate>Mon, 08 Mar 2021 07:39:06 GMT</pubDate>
    <dc:creator>amit1791yadav</dc:creator>
    <dc:date>2021-03-08T07:39:06Z</dc:date>
    <item>
      <title>Splunk CMDB Lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-CMDB-Lookup/m-p/542789#M9766</link>
      <description>&lt;P&gt;We want to override the lookup File as per the below condition.&lt;BR /&gt;&lt;BR /&gt;If File not exist - we don't want to override the lookup file.&lt;BR /&gt;And IF File exist - We can proceed to override the lookup file .&lt;BR /&gt;&lt;BR /&gt;index=siem_test sourcetype="db:cmdb"&lt;BR /&gt;| timechart count by source&lt;BR /&gt;&lt;BR /&gt;IF CMDB part not lost don't override the output lookup and how do we can check the sourcetype is not reporting.&lt;BR /&gt;&lt;BR /&gt;Please suggest any condition which we can use in our search query to populate the result.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 07:39:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-CMDB-Lookup/m-p/542789#M9766</guid>
      <dc:creator>amit1791yadav</dc:creator>
      <dc:date>2021-03-08T07:39:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk CMDB Lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-CMDB-Lookup/m-p/547387#M9861</link>
      <description>&lt;P&gt;This is why I developed a solution to overcome the problem of lookups and/or indexes and/or complex searches. My solution is using a Neo4j graph database in between the source of the information and Splunk. The good thing of the graph database is that it is capable of searching for relationships or the lack of relationships. So you can even combine several sources to give you the context that you need.&lt;/P&gt;&lt;P&gt;I wrote a post about that recently:&amp;nbsp;&lt;A title="SOCs: why they struggle with context" href="https://www.linkedin.com/feed/update/urn:li:activity:6780597932149370880" target="_blank" rel="noopener nofollow noreferrer"&gt;SOCs: why they struggle with context&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 15:00:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-CMDB-Lookup/m-p/547387#M9861</guid>
      <dc:creator>lekanneer</dc:creator>
      <dc:date>2021-04-09T15:00:01Z</dc:date>
    </item>
  </channel>
</rss>

