Splunk Enterprise Security

How to monitor changes in kv store lookups


Hello everyone

I have following problem:
I have set disabled flag in ipintel by following query:
| inputlookup ip
intel where key="js.arcgis.com"
| eval disabled="1"
| outputlookup append=true ip

After some time I discovered that disabled field value disappeared.

My question how I can monitor when and why value isn't anymore in its place.
I thought about using internal indexes.

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.