Hi,
I am new to Splunk. I was wondering if anyone knew if its possible to query a lookup table that has un-parsed data in it. I am looking for a destination IP address (IoC) in a raw packet, but it has not been extracted as a field in Splunk. The source IP is parsed, however is the IP for a workstation.
Basically I want to build a search to lookup some data that has not been extracted, if possible.
Regards,
As far as I am aware without extracting destination IP address in field, you can't match that IP address with lookup table data.