Monitoring Splunk

TrackMe: How to add sourcetypes programatically to AllowList/Block list?

GOB_Bluth
Explorer

I would like the results of a search to populate the allow/block lists in TrackeMe. The lookup file requires a unique key.

Any tips on how to generate that at search time?

Labels (1)
0 Karma

gjanders
SplunkTrust
SplunkTrust

Are you referring to _key?
That's autogenerated for kvstore entries. You don't need to manually generate it 

0 Karma
Get Updates on the Splunk Community!

Get Schooled with Splunk Education: Explore Our Latest Courses

At Splunk Education, we’re dedicated to providing incredible learning experiences that cater to every skill ...

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL  The Splunk AI Assistant for SPL ...

Buttercup Games: Further Dashboarding Techniques (Part 5)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...