Splunk Enterprise

UserSID lookup


I have an index called ‘RDIIS’ with 4 fields named SourceIP , UserSID , DestIP and Host.
Important to know is that UserSID refers to the SID of an active directory user.
I also have a second index ‘ADdump’ with 2 fields UserSID and Username.

Can I combine somehow the two indexes and have this table, so that the UserSID gets associated with the wright Username?

“| Table _time , Host, SourceIP, DestIP , UserSID , Username “

Labels (1)
Tags (2)
0 Karma

Esteemed Legend

Like this:

(index="RDIIS" AND index="ADdump")
| stats values(*) AS * BY UserSID
0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!