Splunk Enterprise

UserSID lookup

christopheducha
Explorer

Hello
I have an index called ‘RDIIS’ with 4 fields named SourceIP , UserSID , DestIP and Host.
Important to know is that UserSID refers to the SID of an active directory user.
I also have a second index ‘ADdump’ with 2 fields UserSID and Username.

Can I combine somehow the two indexes and have this table, so that the UserSID gets associated with the wright Username?

“| Table _time , Host, SourceIP, DestIP , UserSID , Username “

Labels (1)
Tags (2)
0 Karma

woodcock
Esteemed Legend

Like this:

(index="RDIIS" AND index="ADdump")
| stats values(*) AS * BY UserSID
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) v3.54.0

The Splunk Threat Research Team (STRT) recently released Enterprise Security Content Update (ESCU) v3.54.0 and ...

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

New Learning Videos on Topics Most Requested by You! Plus This Month’s New Splunk ...

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...