Splunk Search

How to check which lookup file or table have have an specific field

junier16
Explorer

im looking for the field "is_prohibited=true". This is field is located in one of lookup table, event type, or tag. How can i find out where that filed is  located ?

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @junier16,

at a first sight it seems to be an eventtype, anyway you can search:

  • eventtypes and tags in [Settings -- Eventtypes],
  • for lookups see in [Settings -- Lookups -- Definitions],

for both there's a dedicated search function (remeber to remove the filters on top).

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...