All,
Mind is drawing a blank. I want to normalize netstat output and then do a lookup on the destination fields to see the destination is PCI but for the life of me I am drawing a blank. Any idea what i am doing wrong here?
sourcetype=netstat
| multikv
| rename dest_ip as clientip
| lookup dnslookup clientip
| rename clienthost as dest
| lookup asset_lookup_by_str-dest dest
The auto lookups only work on already extracted deck, dest, dvc. Sonde you are creating src you need to call the macro in the docs http://docs.splunk.com/Documentation/ES/5.1.0/Admin/Verifyassetandidentitydata