Splunk Enterprise Security

Can you do a tstats with Splunk Enterprise Security that would match the value from a lookup table?

AbubakarShahid
New Member

Hello all,

I am working in Splunk ES and i would like to add the capability of getting a match on my URL list.

I have a lookup table that i add malicious URLs in it and I collect it from many different sources. I know Splunk ES has the Threat Intel for URLs but that does not work correctly. It only matches if the URL that I have with the look up table is a 100 percent match with the URL in the data model.

is there a way that i can tell Splunk ES to do a tstats and match the value from the lookup table even if it's only 80 percent of it?

Example:
let say i have abcd.com in the lookup table and in the data model under url field it show as abcd.com/ and just because of the "/" it would not match.

Thanks, looking forward to getting some sort of feed back.

0 Karma
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...

Enterprise Security Content Update (ESCU) | New Releases

In March, the Splunk Threat Research Team had 2 releases of security content via the Enterprise Security ...