Splunk Enterprise Security

How do you send lookup CSV from a forwarder to a search head?

Tylerdygert
Path Finder

Hello,

I am trying to get a lookup CSV file up to my search head from my forwarder. I have created an asset lookup for Enterprise Security on the forwarder using the DB connect app connecting to our SCCM SQL server. Now, the lookup CSV resides on the heavy forwarder where it is useless. I need to get this CSV up to my search head in order to be used as an asset lookup by ES.

Does anyone know how I could accomplish this? Your help is much appreciated.

Note: our Splunk instance has a heavy forwarder (where the file is) that is set to send data to our 2 indexers up in the AWS cloud. These indexers are then searched by our 2 search heads, which are also up in the AWS cloud. The forwarder has no connection to the search head directly.

1 Solution

iandrews_splunk
Splunk Employee
Splunk Employee

If your HF can't connect straight to your SH, you could always ingest the CSV like any other log file.

Then, run a search, from the search head, on the data, create a table in the format you want the lookup to be in, and "outputlookup" the results to a lookup file.

View solution in original post

iandrews_splunk
Splunk Employee
Splunk Employee

If your HF can't connect straight to your SH, you could always ingest the CSV like any other log file.

Then, run a search, from the search head, on the data, create a table in the format you want the lookup to be in, and "outputlookup" the results to a lookup file.

stefan_d
Path Finder

Hi

Is there is perhaps there new capability that allows for this requirement? Ingesting DB data to use for lookups is an option, but I don't think ideal. It consumes license, also additional effort/processing to setup, store and maintain the data in the IDX/C.

I have a similar requirement (and surely it's widely needed) where the DB data source is not reachable to the SH or SHC. All we need is a csv lookup generated from the dbxquery ran on the HF and to forward the object to the SH/C and/or IDX/C.

I suppose one could build a script to achieve this but I rather feel that this could be a helpful feature?

damode
Motivator

I am too in exactly in need for some workaround for this issue. I cant use ldapsearch directly on ES cloud because of this.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

New Case Study Shows the Value of Partnering with Splunk Academic Alliance

The University of Nevada, Las Vegas (UNLV) is another premier research institution helping to shape the next ...

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...