Splunk Search

Managing new field extractions on the fly

aohls
Contributor

Looking for insight as to how people manage when you have macros and other knowledge objects and new logs can get added without us knowing. We have a number of marcos and then a new log is added; which we do not always know, we can miss items due to the filtering within the macro/search on a field extraction. The logging standards are good but we just have new items. 

 

I was thinking of doing a check of the field extractions to find differences through a quick search or some type of lookup; which can then be used to get dashboard items easier which we use a search for now.

Labels (2)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust
The best practice is to define integration/ onboard process which needs to follow before logs can present on splunk.
Another way is create alert or dashboard where you could found new host + source which have added without your knowledge.
r. Ismo

View solution in original post

isoutamo
SplunkTrust
SplunkTrust
The best practice is to define integration/ onboard process which needs to follow before logs can present on splunk.
Another way is create alert or dashboard where you could found new host + source which have added without your knowledge.
r. Ismo

aohls
Contributor

That is what should happen, unfortunately it doesn't always. I setup a morning report to present anything new to me.

0 Karma
Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...