Getting Data In

Creating sequence templates in Splunk

VidhyaChris
New Member

Hi all,

I want to create a Sequent template  that triggers when two correlation searches triggers for the same source IP.

  • Correlation Search 1: EDR Detection
  • Correlation Search 2: Traffic to suspicious URL
  • Fields of Interest from Correlation Search 1:Source IP, File Name, File Path, File Hash etc
  • Fields of Interest from Correlation Search 2:Source IP, URL, URL_Domain, Destination IP etc

How can I get the fields of interest from correlation search 2 in the sequenced events? The ‘Output Fields’ session in the Sequence template is accepting only the ‘status labels’ defined in the ‘start’ session(ie, fields from Correlation Search 1).

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...