Getting Data In

monitoring directory files

neroi
Explorer

Hello!
Need help with monitoring
We monitor the directory and load from the text files the data of the following format:

http://immage.biz/image/SVoO

We need to complete the record of information about the IP address with resolve by name of the PC (armName) after adding the event data.
How to make such an enrichment and also remove some of the fields that do not carry useful information for us?

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

You can enrich your data using lookup using either DNS or a local lookup file. To use DNS:

... | lookup dnslookup clienthost as armName OUTPUT clientip as armIP | ...

To use a local file you will need a CSV file with two fields: armName and armIP. Upload that file to your search head and use this SPL:

... | lookup armlookup.csv armName OUTPUT armIP | ...

Use the fields command to remove unwanted fields at search time.

... | fields - field6 field7 | ...

There are ways to prevent indexing of fields at index time, but we'd have to know about how you ingest this file. Share your props.conf settings, if you can.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

You can enrich your data using lookup using either DNS or a local lookup file. To use DNS:

... | lookup dnslookup clienthost as armName OUTPUT clientip as armIP | ...

To use a local file you will need a CSV file with two fields: armName and armIP. Upload that file to your search head and use this SPL:

... | lookup armlookup.csv armName OUTPUT armIP | ...

Use the fields command to remove unwanted fields at search time.

... | fields - field6 field7 | ...

There are ways to prevent indexing of fields at index time, but we'd have to know about how you ingest this file. Share your props.conf settings, if you can.

---
If this reply helps you, Karma would be appreciated.

neroi
Explorer

Hello! Thank you for answer.

We use the first method now. But it gets the value of the address at the current moment when the search query occurs. And we need to store the value obtained at the time of receiving the data.

0 Karma

neroi
Explorer

any comment to this question?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Your image of the data is broken. Please try copy-paste rather than inserting an image.

---
If this reply helps you, Karma would be appreciated.
0 Karma

neroi
Explorer

thanks for your comment.
Edited

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...