Splunk Search

Data wherehousing - Can Splunk report on previous device-account mapping?

maverick
Splunk Employee
Splunk Employee

Suppose that I have events for my devices being splunked and each device is associated with an account ID located in a database.

We have a scenario as follows:

  • - A device starts out associated with one account (say account “A”) from Feb-March
  • - The device THEN gets re-associated to another account (say Account “B”) in April

    Reports generated for Feb-March must associate the Account “A” database information with the device, whereas any report after March must associate the Account “B” database information with the device.

    How would splunk handle this scenario and/or need to be setup to enforce these reporting requirements? Any experience or best practices would be greatly appreciated.
  • DrewO
    Splunk Employee
    Splunk Employee

    Hey Maverick,

    For this one you'd want a time-based lookup. See docs here: http://www.splunk.com/base/Documentation/latest/Knowledge/Addfieldsfromexternaldatasources#Set_up_a_...

    Look for other answers for best practices on this.

    D

    maverick
    Splunk Employee
    Splunk Employee

    So you are saying I could match the event time on a temporal month and year based field? If so, then I could maintain the new mappings as they change in the lookup file, correct?

    0 Karma
    Career Survey
    First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

    Can’t make it to .conf25? Join us online!

    Get Updates on the Splunk Community!

    Community Content Calendar, September edition

    Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

    Splunkbase Unveils New App Listing Management Public Preview

    Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

    Leveraging Automated Threat Analysis Across the Splunk Ecosystem

    Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...