I'm new to Splunk. I'm not much familiar with the query search and lookup files. I have a custom IOC file with IPs & URLs and I want to search if there was any traffic to that destination. I went through few of the blogs and the suggestion was to create a csv lookup file.
Could you please let me know if it is the correct approach or is there any better way to search the IOCs?