Splunk Enterprise Security

What is the best way to build searches and alerting in a Hyper-V environment in which VMs pull MAC address ?

gg74
Engager

What is the best way to deal with building searches and alerting in a Hyper-V environment in which VMs pull MAC address from a pool controlled by the cluster nodes?  Is setting all of my VMs to use static MAC addresses best practice (this is a large undertaking and would require maintenance) or is there a better way to do this?  Should I rely on another variable to track these assets?

Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

If you want a deterministic way to track assets, don't use a non-deterministic way of identifying the assets.

0 Karma

gg74
Engager

Is there a better variable to use than the MAC address?  Something that doesn't rely on manual intervention to set?  Is the GUID or device name the standard?  Just looking options I may not be aware of.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

It depends how your assets are set up - often a qualified host name is unique (enough) in your environment to distinguish between different hosts.

Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...