Getting Data In

Creating sequence templates in Splunk

VidhyaChris
New Member

Hi all,

I want to create a Sequent template  that triggers when two correlation searches triggers for the same source IP.

  • Correlation Search 1: EDR Detection
  • Correlation Search 2: Traffic to suspicious URL
  • Fields of Interest from Correlation Search 1:Source IP, File Name, File Path, File Hash etc
  • Fields of Interest from Correlation Search 2:Source IP, URL, URL_Domain, Destination IP etc

How can I get the fields of interest from correlation search 2 in the sequenced events? The ‘Output Fields’ session in the Sequence template is accepting only the ‘status labels’ defined in the ‘start’ session(ie, fields from Correlation Search 1).

Tags (1)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Maximizing the Value of Splunk ES 8.x

Splunk Enterprise Security (ES) continues to be a leader in the Gartner Magic Quadrant, reflecting its pivotal ...

Operationalizing TDIR: Building a More Resilient, Scalable SOC

Optimizing SOC workflows with a unified, risk-based approach to Threat Detection, Investigation, and Response ...