Hello Guys,
I have some doubt about data event correlation. i am getting events from different different security vendors like Area1 bitdefender, crowdstrike, cloudflare. now i wants in my splunk the event correlation should happen automatically. suppose any incident happen in any endpoint it should correlate that event with other data sources as well. not sure how to achieve this
or i am getting the events from different vendor so in some event the IP is listed as source IP in some event it listed computer IP to normalize it for all the data sources so it will be the same for all data sources.
any lead will be appricatebale
Thanks
Jeewan
@Jeewan Regarding the data normalization part of your question you should check out Splunk Common Information Model (CIM) Overview of the Splunk Common Information Model - Splunk Documentation
With that you should solve the first part your question.