<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: vendor_action Field in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/vendor-action-Field/m-p/543626#M153988</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232321"&gt;@splunkymcsnypr&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Common Information Model has an action field that expects "allowed", "blocked" or "teardown" values. Device that sends these events with action&amp;nbsp;field may have other convention like "accept", "deny", "close", etc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;vendor_action&lt;/STRONG&gt; field keeps original event action values that one may need to know original action value.&lt;/P&gt;</description>
    <pubDate>Sat, 13 Mar 2021 09:54:12 GMT</pubDate>
    <dc:creator>scelikok</dc:creator>
    <dc:date>2021-03-13T09:54:12Z</dc:date>
    <item>
      <title>vendor_action Field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/vendor-action-Field/m-p/543182#M153872</link>
      <description>&lt;P&gt;Hi!&lt;BR /&gt;I'm trying to find more information about the vendor_action field, however I've not managed to do so with much success. If anyone has any insight in terms of cyber value and mapping to use cases that would be really helpful. Does there exist a taxonomy for this field?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Mar 2021 11:00:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/vendor-action-Field/m-p/543182#M153872</guid>
      <dc:creator>splunkymcsnypr</dc:creator>
      <dc:date>2021-03-10T11:00:33Z</dc:date>
    </item>
    <item>
      <title>Re: vendor_action Field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/vendor-action-Field/m-p/543626#M153988</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232321"&gt;@splunkymcsnypr&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Common Information Model has an action field that expects "allowed", "blocked" or "teardown" values. Device that sends these events with action&amp;nbsp;field may have other convention like "accept", "deny", "close", etc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;vendor_action&lt;/STRONG&gt; field keeps original event action values that one may need to know original action value.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Mar 2021 09:54:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/vendor-action-Field/m-p/543626#M153988</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-03-13T09:54:12Z</dc:date>
    </item>
  </channel>
</rss>

