Splunk Enterprise Security

How to enrich notable events in ES?

cjharmening
Loves-to-Learn

Hello all,

 We are wanting to enrich events as they become notables in ES before they are sent onto Mission control. Thoughts being, enrich the event via some sort of search ( all the data will be in splunk already) to add , DNS, DHCP, Threat intel and some endpoint data. 

 

 Is it possible to have a search run for the notable index to gather information from other indexes and add them to the notable event?  If so I would love to discuss.

 

 

Tags (2)
0 Karma

JohnEGones
Path Finder
0 Karma
Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...