<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple log files with several keys in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Multiple-log-files-with-several-keys/m-p/180890#M52129</link>
    <description>&lt;P&gt;The question is indeed about a key present in one file, referencing a vuln id, on which details are present in another file with this key, about a computer with another key, for an IP, on which a different key is present in another table/file, refering to another key/ID... you see ?  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Is there any other method for the &lt;STRONG&gt;LINK&lt;/STRONG&gt; between files, and for &lt;STRONG&gt;search enhancement&lt;/STRONG&gt; ?&lt;/P&gt;

&lt;P&gt;Thansk for your answers !&lt;/P&gt;</description>
    <pubDate>Tue, 11 Mar 2014 09:20:04 GMT</pubDate>
    <dc:creator>renaudleroy</dc:creator>
    <dc:date>2014-03-11T09:20:04Z</dc:date>
    <item>
      <title>Multiple log files with several keys</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multiple-log-files-with-several-keys/m-p/180889#M52128</link>
      <description>&lt;P&gt;Hi all!&lt;/P&gt;

&lt;P&gt;I've got different log files (in fact, extracts from different databases) from a data warehouse (abstractly a big database) :&lt;BR /&gt;
ex:&lt;BR /&gt;
database1 (asset management) give :&lt;BR /&gt;
 - a list of asset_management_computers&lt;BR /&gt;
 - a list of vulnerabilities for these computers&lt;BR /&gt;
 - maybe a different file with vulns ids and details&lt;/P&gt;

&lt;P&gt;database2 (antivirus) gives :&lt;BR /&gt;
 - a list of computers for the antivirus product&lt;BR /&gt;
 - a list of infections&lt;/P&gt;

&lt;P&gt;The goal is to be able to have information for a source IP, or a hostname, and extract the results (vulnerabilities and mapped potential AV  exploiting these vulnerabilities) from splunk.&lt;/P&gt;

&lt;P&gt;The problem is that there are different Ids for individual computers (not the same ID for asset management and for AV) and cross-link IDs, I mean: a vulnerability is identified and detailed in a 3rd file, but the ID vulnerability is present in the extracted list of vulnerabilities and the AV has different keys present in different files. So i need to find a &lt;STRONG&gt;LINK&lt;/STRONG&gt; to map between these different reference and goal is to search e.g for an IP and find the corresponding vulnerabilities and virus alertes that tried to exploit them.&lt;BR /&gt;
You see ?&lt;/P&gt;

&lt;P&gt;My approach was atm to index (in different indexes) the extracted files from databases :&lt;BR /&gt;
 - create an index named asset_management_computers&lt;BR /&gt;
 - create an index named asset_management_vulns&lt;BR /&gt;
 - create and index named asset_management_vulns_details&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;create an index named av_computers&lt;/LI&gt;
&lt;LI&gt;create an index named av_infections&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Then inject logs directly in the corresponding indexes.&lt;BR /&gt;
And for search e.G i search for all infos referring to an IP source :&lt;BR /&gt;
&lt;STRONG&gt;index = asset_management_* or index = av_* 192.168.0.1&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;I'll thus be able to find the results corresponding to events for the indexed files (vulns, ids, av infeections..etc)&lt;/P&gt;

&lt;P&gt;Is there any other method for the &lt;STRONG&gt;LINK&lt;/STRONG&gt; between files, and for &lt;STRONG&gt;search enhancement&lt;/STRONG&gt; ?&lt;/P&gt;

&lt;P&gt;Thansk for your answers !&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:05:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multiple-log-files-with-several-keys/m-p/180889#M52128</guid>
      <dc:creator>renaudleroy</dc:creator>
      <dc:date>2020-09-28T16:05:18Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple log files with several keys</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multiple-log-files-with-several-keys/m-p/180890#M52129</link>
      <description>&lt;P&gt;The question is indeed about a key present in one file, referencing a vuln id, on which details are present in another file with this key, about a computer with another key, for an IP, on which a different key is present in another table/file, refering to another key/ID... you see ?  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Is there any other method for the &lt;STRONG&gt;LINK&lt;/STRONG&gt; between files, and for &lt;STRONG&gt;search enhancement&lt;/STRONG&gt; ?&lt;/P&gt;

&lt;P&gt;Thansk for your answers !&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2014 09:20:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multiple-log-files-with-several-keys/m-p/180890#M52129</guid>
      <dc:creator>renaudleroy</dc:creator>
      <dc:date>2014-03-11T09:20:04Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple log files with several keys</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multiple-log-files-with-several-keys/m-p/180891#M52130</link>
      <description>&lt;P&gt;Check the join command to link results from 2 searches over a field, or if you have a database define a database lookup.&lt;/P&gt;

&lt;P&gt;join : &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Join"&gt;http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Join&lt;/A&gt;&lt;BR /&gt;
lookup to static file : &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Lookup"&gt;http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Lookup&lt;/A&gt;&lt;BR /&gt;
database lookup using dbconnect : &lt;A href="http://docs.splunk.com/Documentation/DBX/latest/DeployDBX/Abouttheconnector"&gt;http://docs.splunk.com/Documentation/DBX/latest/DeployDBX/Abouttheconnector&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Otherwise another solution is to use a subsearch to return conditions for the main search, but it is better suited for small sub sets of events than all of your ips ....&lt;BR /&gt;
see &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Search/Aboutsubsearches"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Search/Aboutsubsearches&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2014 15:39:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multiple-log-files-with-several-keys/m-p/180891#M52130</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2014-03-11T15:39:31Z</dc:date>
    </item>
  </channel>
</rss>

