Hi Gcusello, output is blank for below query. index=*asa* [search index=otx sourcetype="otx:indicator" type=IPv4 indicator=* |rename indicator as dst_ip|fields dst_ip]|dedup src_ip|table src_ip. how ever i manually ping/trace 1 ip address which is in indicator field for testing purpose and i can see those IP in ASA logs in splunk. Thanks shashi
... View more
yes , you correct , but i am not getting desire output. i am attaching ASA index output , otx index output and Correlation SPL which i prepared as you suggested. ASA index.png otx index.png Correlation SPL
... View more