Splunk Enterprise Security

Splunk Enterprise Security: How to construct an inputlookup search that will display ES identity information from their usernames?

Path Finder

I have a lookup with 461 usernames. I want to input the lookup to Splunk and display corresponding First and Last name from Splunk Enterprise Security Identities.

Any ideas how to construct that search?

|inputlookup users | `identities`

user
xxxx
yyyy
zzzz
...
0 Karma
1 Solution

Builder

Try this one.

|inputlookup users.csv|fields user|eval user=lower(user)|join type=left user [datamodel("Identity_Management", "All_Identities")| drop_dm_object_name("All_Identities")|mvexpand identity|rename identity as user|eval user=lower(user)]|table user first last

View solution in original post

Builder

Try this one.

|inputlookup users.csv|fields user|eval user=lower(user)|join type=left user [datamodel("Identity_Management", "All_Identities")| drop_dm_object_name("All_Identities")|mvexpand identity|rename identity as user|eval user=lower(user)]|table user first last

View solution in original post

Path Finder

the search was missing `` around dropdmobjectname("AllIdentities")

Corrected and run it but it does not populate first and last name.

0 Karma

Builder

try updated one..

0 Karma

Path Finder

Kiran,

Apologies, I did not noticed the updated search.
It was great, producing expected results !

Thanks!

0 Karma