Splunk Enterprise Security

Can you do a tstats with Splunk Enterprise Security that would match the value from a lookup table?

AbubakarShahid
New Member

Hello all,

I am working in Splunk ES and i would like to add the capability of getting a match on my URL list.

I have a lookup table that i add malicious URLs in it and I collect it from many different sources. I know Splunk ES has the Threat Intel for URLs but that does not work correctly. It only matches if the URL that I have with the look up table is a 100 percent match with the URL in the data model.

is there a way that i can tell Splunk ES to do a tstats and match the value from the lookup table even if it's only 80 percent of it?

Example:
let say i have abcd.com in the lookup table and in the data model under url field it show as abcd.com/ and just because of the "/" it would not match.

Thanks, looking forward to getting some sort of feed back.

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...