Splunk Search

Using network topology information for search

evgenyv
Explorer

I develop an IT environment management system and considering using splunk for event analysis. I'd like to be able to use the network topology as an additional input for root cause analysis. For example, I'm interested to search for events from devices connected to the certain switch.
Initially, I was thinking about using a workflow and extending all events by information from the external topology repository. However, my concerns are about performance degradation and significant data volume increase in this case.
Is there is a way to to keep the topology data in splunk and to use it in the search ?

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Depending on your network topo, there are a few options and ways to approach this.

One of the simplest would be to keep a cmdb that has connection mapping. In Splunk, this would be easiest in a csv (or database.) And then you can enrich your data as its searched by adding fields based on hostnames and ports in the lookup file and events.

There are other options here, depending on your current network stack. There are existing apps for Nagios, Snort etc.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...