So apologies in advance if this question really has to do with my general ignorance of Splunk - I'm just getting my feet wet.
I've got Splunk for Asset Discovery set up, have run a couple of test scans with custom targets and am getting results.
In my intended usage, it would be useful for me to be able to filter/search by a label that relates to the specific subnet I'm scanning - I have several hundred subnets that I need to scan, and although I would guess I can search by the subnet info (haven't worked that out yet) it would be more useful to be able to immediately filter by Location XYZ (I would have a one-to-one mapping of locations to subnets), or better yet to be able to generate reports showing all locations(subnets) that responded (or didn't), or had a change in the last day, etc.
I can't see how I could do that with the fields that are available to me when cloning the default inputs for this app to create custom inputs.
I'm wondering if I could use the Host Field shown under "more settings", but unsure whether this would have unintended effects.
Assuming that field is one I can search for and filter/sort by, it would probably get the job done for me, if there are no unintended effects.
Thanks for any help! If there is a better path to the same result, I'd love to hear it.
... View more