Splunk Search

Using host tags (or similar) when searching on fields?

Ayn
Legend

I have a number of hosts that have a certain tag on them (let's say "sensitive"). I want to look for account lockout events involving these hosts. Normally this would be simple, just using a query like 'eventtype="winaccountlockout" tag="host::sensitive"' - the twist here is that the actual event occurs not on the hosts themselves but rather on the domain controllers. So, i want to search for account lockout events on the domain controllers that involve the hosts i have that are marked as 'sensitive'.

I was thinking something like 'eventtype="winaccountlockout" Caller_Machine_Name=' where the list is somehow taken from the list of hosts with the "host::sensitive" tag. Is there any way to do that, or solve the problem in another way?

Tags (2)
1 Solution

ftk
Motivator

Use a subsearch as such:

eventtype="winaccountlockout" [search tag::host=sensitive | dedup host | rename host as Caller_Machine_Name | fields Caller_Machine_Name  | format]

Or if you don't want to pass the subsearch results back as the specific field (Caller_Machine_Name) just do

eventtype="winaccountlockout" [search tag::host=sensitive | dedup host | fields host | rename host as search]

View solution in original post

ftk
Motivator

Use a subsearch as such:

eventtype="winaccountlockout" [search tag::host=sensitive | dedup host | rename host as Caller_Machine_Name | fields Caller_Machine_Name  | format]

Or if you don't want to pass the subsearch results back as the specific field (Caller_Machine_Name) just do

eventtype="winaccountlockout" [search tag::host=sensitive | dedup host | fields host | rename host as search]

gkanapathy
Splunk Employee
Splunk Employee

Seems like this would be a good place to consider using lookup tables. Possibly you could even replace the tags with lookup table entries.

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...