Splunk Search

vendor_action Field

splunkymcsnypr
Engager

Hi!
I'm trying to find more information about the vendor_action field, however I've not managed to do so with much success. If anyone has any insight in terms of cyber value and mapping to use cases that would be really helpful. Does there exist a taxonomy for this field?

Labels (3)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @splunkymcsnypr,

Common Information Model has an action field that expects "allowed", "blocked" or "teardown" values. Device that sends these events with action field may have other convention like "accept", "deny", "close", etc. 

vendor_action field keeps original event action values that one may need to know original action value.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...