Splunk Enterprise Security

Can you do a tstats with Splunk Enterprise Security that would match the value from a lookup table?

AbubakarShahid
New Member

Hello all,

I am working in Splunk ES and i would like to add the capability of getting a match on my URL list.

I have a lookup table that i add malicious URLs in it and I collect it from many different sources. I know Splunk ES has the Threat Intel for URLs but that does not work correctly. It only matches if the URL that I have with the look up table is a 100 percent match with the URL in the data model.

is there a way that i can tell Splunk ES to do a tstats and match the value from the lookup table even if it's only 80 percent of it?

Example:
let say i have abcd.com in the lookup table and in the data model under url field it show as abcd.com/ and just because of the "/" it would not match.

Thanks, looking forward to getting some sort of feed back.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...