I am learning Splunk (early stages). I have been playing around with this search for the past 2 hours with little success.
I am running this query to get an ip address of the workstation this person is using:
index=fortinet* user=XXXX* | top limit=1 sip | table sip
I am trying to tie this search in with another index search ( index=wineventlog_pc ) and use that ip address as the source to find the actual name of the workstation being used.
Any help or insights would be awesome. Thank you
... View more