Splunk Enterprise Security

Can you do a tstats with Splunk Enterprise Security that would match the value from a lookup table?

AbubakarShahid
New Member

Hello all,

I am working in Splunk ES and i would like to add the capability of getting a match on my URL list.

I have a lookup table that i add malicious URLs in it and I collect it from many different sources. I know Splunk ES has the Threat Intel for URLs but that does not work correctly. It only matches if the URL that I have with the look up table is a 100 percent match with the URL in the data model.

is there a way that i can tell Splunk ES to do a tstats and match the value from the lookup table even if it's only 80 percent of it?

Example:
let say i have abcd.com in the lookup table and in the data model under url field it show as abcd.com/ and just because of the "/" it would not match.

Thanks, looking forward to getting some sort of feed back.

0 Karma
Get Updates on the Splunk Community!

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...

AppDynamics is now part of Splunk Ideas

Hello Splunkers, We have exciting news for you! AppDynamics has been added to the Splunk Ideas Portal. Which ...

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...