Splunk Search

How to edit my search to find if any userIDs in a lookup table exist in URL strings in proxy logs?

pdumblet
Explorer

I have a lookup table that contains all userIDs from Active Directory. I have proxy logs that I would like to determine if any of our corporate userIDs show up in the URL string. URL is a field that is extracted from the logs.

This is the search string I have so far:

index=proxy http_method=POST action!=blocked | lookup ad_identity.csv identity as url | table _time, identity, url, src_ip

I am not getting the results I expected as no filtering based on the lookup table is currently occurring.

Any suggestions would be greatly appreciated.

0 Karma
1 Solution

sundareshr
Legend

You will have to extract the user name from the url and then filter based on the lookup file. Something like this should work

index=proxy http_method=POST action!=blocked | rex field=url "appropriate regex to extract username here" | search [| inputlookup ad_identity.csv | rename identity as user | fields user ]

If you need help with regex, please share some sample events.

View solution in original post

sundareshr
Legend

You will have to extract the user name from the url and then filter based on the lookup file. Something like this should work

index=proxy http_method=POST action!=blocked | rex field=url "appropriate regex to extract username here" | search [| inputlookup ad_identity.csv | rename identity as user | fields user ]

If you need help with regex, please share some sample events.

aaraneta_splunk
Splunk Employee
Splunk Employee

Hi @pdumblet - I saw that you up-voted sundareshr's answer but didn't accept it. Did this solution help resolve your question? If yes, please be sure to close out this question by click "Accept" so that other users can easily find it if they're facing the same problem. If no, please leave some feedback in a comment. Thanks!

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...