Hi There,
I am currently looking at a search within Splunk Security Essentials (Concentration of Attacker Tools by Filename).
The search mentions a file named "tools.csv", which I assume is a list of the attacker tools mentioned in the title of the search.
Is there any way that I can access the contents of the CSV file? Purely because I want to see which tools are listed.
Any help would be appreciated,
Jamie
You could try
| inputlookup tools.csv
Hi There,
That worked 🙂
Cheers,
Jamie