<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identifying user based on IP Address/ Hostname in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Identifying-user-based-on-IP-Address-Hostname/m-p/547036#M155079</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/147711"&gt;@jonaclough&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I think the best way is create a identity and asset lookup table to manage better the logs flow.&lt;/P&gt;&lt;P&gt;Please check how works lookup table:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/DSP/1.2.0/FunctionReference/Lookup" target="_blank"&gt;https://docs.splunk.com/Documentation/DSP/1.2.0/FunctionReference/Lookup&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 07 Apr 2021 13:49:35 GMT</pubDate>
    <dc:creator>aasabatini</dc:creator>
    <dc:date>2021-04-07T13:49:35Z</dc:date>
    <item>
      <title>Identifying user based on IP Address/ Hostname</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Identifying-user-based-on-IP-Address-Hostname/m-p/547034#M155078</link>
      <description>&lt;DIV class="lia-quilt-row lia-quilt-row-message-subject"&gt;&lt;DIV class="lia-quilt-column lia-quilt-column-24 lia-quilt-column-single lia-quilt-column-message-subject-content"&gt;&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-single"&gt;&lt;DIV class="topic-subject-wrapper"&gt;&lt;DIV class="lia-message-subject lia-component-message-view-widget-subject"&gt;&lt;DIV class="MessageSubject"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="lia-quilt-row lia-quilt-row-message-author"&gt;&lt;DIV class="lia-quilt-column lia-quilt-column-20 lia-quilt-column-left lia-quilt-column-message-author-content"&gt;&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-left"&gt;&lt;DIV class="lia-message-author-avatar lia-component-author-avatar lia-component-message-view-widget-author-avatar"&gt;&lt;DIV class="UserAvatar lia-user-avatar lia-component-common-widget-user-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="lia-quilt-row lia-quilt-row-message-body"&gt;&lt;DIV class="lia-quilt-column lia-quilt-column-24 lia-quilt-column-single lia-quilt-column-message-body-content"&gt;&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-single"&gt;&lt;DIV class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;P&gt;We need to add users to our (unauthenticated) internal proxy logs. Currently the proxy logs only identity the initiator by IP address.&lt;/P&gt;&lt;P&gt;We have DHCP and/or windows desktop logs to link the IP to a hostname. We have windows logon events which contain the hostname and user fields. Multiple users are able to log onto certain hosts and indeed might be logged on at the same time (using fast user switching).&lt;/P&gt;&lt;P&gt;Has anyone any advice on how to solve this problem at scale (30 million events/hour)&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 07 Apr 2021 13:23:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Identifying-user-based-on-IP-Address-Hostname/m-p/547034#M155078</guid>
      <dc:creator>jonaclough</dc:creator>
      <dc:date>2021-04-07T13:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: Identifying user based on IP Address/ Hostname</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Identifying-user-based-on-IP-Address-Hostname/m-p/547036#M155079</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/147711"&gt;@jonaclough&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I think the best way is create a identity and asset lookup table to manage better the logs flow.&lt;/P&gt;&lt;P&gt;Please check how works lookup table:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/DSP/1.2.0/FunctionReference/Lookup" target="_blank"&gt;https://docs.splunk.com/Documentation/DSP/1.2.0/FunctionReference/Lookup&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 13:49:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Identifying-user-based-on-IP-Address-Hostname/m-p/547036#M155079</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-04-07T13:49:35Z</dc:date>
    </item>
    <item>
      <title>Re: Identifying user based on IP Address/ Hostname</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Identifying-user-based-on-IP-Address-Hostname/m-p/547056#M155082</link>
      <description>&lt;P&gt;That's a link to DSP which is not relevant.&amp;nbsp;Identity and Asset lookups are not going to work either as users do not own hosts.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not sure if you are trying to grab Karma for your own purposes but your response is in no way relevant or helpful.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 15:05:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Identifying-user-based-on-IP-Address-Hostname/m-p/547056#M155082</guid>
      <dc:creator>jonaclough</dc:creator>
      <dc:date>2021-04-07T15:05:30Z</dc:date>
    </item>
    <item>
      <title>Re: Identifying user based on IP Address/ Hostname</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Identifying-user-based-on-IP-Address-Hostname/m-p/547058#M155083</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/147711"&gt;@jonaclough&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sorry if my solution doesn't work for you or isn't relevant,however I did not like your controversial comment.&lt;BR /&gt;I tried to help, if my help doesn''t works please try to explain better.&lt;/P&gt;&lt;P&gt;how many sources are involved?&lt;/P&gt;&lt;P&gt;why Identity lookup doesn't works to with users and associated IP?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;maybe your enviroment have many record in your lookup you can think to migrate to kvstore&lt;/P&gt;&lt;P&gt;Please let me know&amp;nbsp;I am a splunk enthusiast I don't need karma for my&amp;nbsp;&lt;SPAN&gt;purposes&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 15:30:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Identifying-user-based-on-IP-Address-Hostname/m-p/547058#M155083</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-04-07T15:30:11Z</dc:date>
    </item>
    <item>
      <title>Re: Identifying user based on IP Address/ Hostname</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Identifying-user-based-on-IP-Address-Hostname/m-p/548802#M155700</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222210"&gt;@aasabatini&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have no doubt you are an enthusiast (what's not to love about splunk?! &lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;), but it is curious that there are a number of accounts whose sole purpose seems to be to keep you in the top 4 karma authors. Just sayin'&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 14:37:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Identifying-user-based-on-IP-Address-Hostname/m-p/548802#M155700</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-04-21T14:37:53Z</dc:date>
    </item>
  </channel>
</rss>

