Splunk Enterprise Security

Enterprise Security: What are the extraction fields?

danielbb
Motivator

We wonder what the identity, Asset, File and URL Extraction fields are in the Notable set-up of the correlation search.

alt text

0 Karma

DavidHourani
Super Champion

Hi @danielbb 

File and URLThese correspond to the artifact creation flow on the investigation workbench. Instead of creating a file or URL artifact on the workbench by hand, you can specify which fields should be used to create artifacts automatically when you add a notable to the investigation workbench.

 

More details here:

https://docs.splunk.com/Documentation/ES/latest/Admin/Customizeinvestigations#Set_up_artifact_extrac...

couilda
Engager

If the Identity and Asset extraction features pull their information from the assets/identities lookup tables where does the File and URL extraction features pull their information from?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Those fields are where you tell the Notable where to find fields of each type. That is, the fields it should use for Identity information are 'src_user', and 'user'; the fields containing Asset information are 'src', 'dest', 'dvc', and 'orig_host'; and so on.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...