Splunk by default cannot do event aggregation in this way, HOWEVER, ArcSight NiFi , and cribl can. In the case of ArcSight , they do not charge for the use of their connectors which do this aggregation function but probably using them without using the entire product is a violation of their TOS. In the case of cribl it is super easy but it does cost money (let me know if you need help, we are a VAR). In the case of NiFi , it is complicated but free. The "right" answer is probably cribl because it is specifically built for doing this kind of thing and connecting to Splunk.
... View more