Splunk Enterprise Security

ES - Threat Activity Search add Host field

mmoermans
Path Finder

When matching against threat intel the notable events only shows the source and destination of the matched event. Is there a way to make the correlation search only find specific events with a specific host and show the host in the notable event?

For example, showing the source, destination and that it occured on firewall 2.

0 Karma
1 Solution

lakshman239
Influencer

I assume if you use a datamodel (e.g Network_Traffic), you can use the 'dvc' value which should indicate the firewall/host on which the event was noticed.

View solution in original post

lakshman239
Influencer

I assume if you use a datamodel (e.g Network_Traffic), you can use the 'dvc' value which should indicate the firewall/host on which the event was noticed.

Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...