Archive

Splunk Join help

Path Finder

Hi, We are looking to join INDICATOR VALUE from lookup table to the search and needs to find out if a value is same.

Below is sample query I am currently doing:

 |inputlookup IOC.csv
|eval INDICATOR_VALUE=replace(INDICATOR_VALUE,"[\[\]]","")
|fields INDICATOR_VALUE
|join type=left INDICATOR_VALUE[search index=bank_nagw_preprod sourcetype=access_log clientip=*
|dedup clientip
|table clientip
|rename clientip as INDICATOR_VALUE
|fields INDICATOR_VALUE]

Thanks

Tags (1)
0 Karma

Communicator

Doesn't the following search already delivers what you want?

search index=bank_nagw_preprod sourcetype=access_log
[ | inputlookup IOC.csv | eval INDICATOR_VALUE=replace(INDICATOR_VALUE,"[\[\]]","") |fields INDICATOR_VALUE | rename INDICATOR_VALUE AS clientip ]

Communicator

Without using "join".

0 Karma