Splunk Search

vendor_action Field

splunkymcsnypr
Engager

Hi!
I'm trying to find more information about the vendor_action field, however I've not managed to do so with much success. If anyone has any insight in terms of cyber value and mapping to use cases that would be really helpful. Does there exist a taxonomy for this field?

Labels (3)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @splunkymcsnypr,

Common Information Model has an action field that expects "allowed", "blocked" or "teardown" values. Device that sends these events with action field may have other convention like "accept", "deny", "close", etc. 

vendor_action field keeps original event action values that one may need to know original action value.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...