Splunk Search

Log4j matching

Papemalik1
New Member

Hello,

I have 2 lookups, L0011 which contains all (Known) products with the vulnerability Log4shell and L0012 with all the products and assets that I have in house.

I would like to join these 2 lookups to have at the end: all vulnerable products that I have and the assets for each products.

But so far the joining is not working. I have used the command join and lookup, i have added wildcard on the lookup definition  also, but it's not working either. (the results is not exhaustive, i have very few matches)

the main issue is that the names of the products don't match identically (even with wildcard).

Do you guys have any idea on how could I do matching with my two lookups?

do not hesiate to ask if I need to clarify more.

Thanks a lot in advance

Labels (2)
0 Karma

johnhuang
Motivator

I would consider the approach of normalizing your data -- either clean up the source or lookup products field to match the other.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...