Splunk Search

Help with inputintelligence command?

dm1
Contributor

Below is my spl

 

|from datamodel:"Threat_Intelligence".""Threat_Activity"
|dedup threat_match_field,threat_match_value
|search NOT
[|inputintelligence cisco_top_million_sites
|rename domain as threat_match_value
|table threat_match_value]

 

 Explanation: basically from any threat activity detected, I want to remove false positives domains detected by using the cisco_top_million_sites as a reference to exclude FP domains.

However, the part where domains in threat_match_value is compared to domains in cisco_top_million_sites  threat intel file, some domains are not getting excluded. Its mainly the content.dropboxapi.com domain which still appears in the results even though its in the threat intel file while other sub domains of the dropboxapi.com are excluded.

Can someone please help with fixing this ?

Labels (2)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

Subsearches can only return max 10,000 results, so if inputintelligence is returning more rows than that, you will not restrict your main search correctly. You would probably have to use a lookup created from inputintelligence and do

| lookup file domain as threat_match_value OUTPUT domain as found
| where isnull(found)

View solution in original post

bowesmana
SplunkTrust
SplunkTrust

Subsearches can only return max 10,000 results, so if inputintelligence is returning more rows than that, you will not restrict your main search correctly. You would probably have to use a lookup created from inputintelligence and do

| lookup file domain as threat_match_value OUTPUT domain as found
| where isnull(found)

dm1
Contributor

Thanks alot!!!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Data Drivers: How We're Streaming Real-Time F1 Telemetry Directly into Splunk ...

Data Drivers: Every Lap Tells a Story The Spectacle Two F1 racing sims go head-to-head on the .conf26 show ...

Data Management Digest – July 2026

  Welcome to the July 2026 edition of Data Management Digest! As your trusted partner in data innovation, the ...