Splunk Enterprise Security

Format an asset list in Splunk Enterprise Security

evelenke
Contributor

Hi Splunkers,

As it's stated in documentation, fields like ip, mac, dns in Asset lookup should be "A pipe-delimited list of single ... " asset values.
Should this pipe-delimited list be done manually or should I expect Splunk to cook it automatically from different sources, for example when we have the following scope:

  • CMDB (available asset lookup fields: nt_host (dns), owner)
  • DNS Records (ip, dns)
  • DHCP Records (ip,mac, dns)
  • Windows Security Authentication (nt_host, owner)
  • Network Identity Services (ip, owner)

The savedsearch just concatenates the lists, no matching and mixing happens, so the same hostname may occur many times, is there another required approach from ES side? Do I miss smth or we have to prepare appropriate format for final input?

0 Karma
1 Solution

starcher
SplunkTrust
SplunkTrust

Splunk ES will not dedup assets across input files. Let's say you have an IP that has multiple hostnames. Put them in the dns field pipe delimited and only have that IP in one row of one file.

View solution in original post

0 Karma

starcher
SplunkTrust
SplunkTrust

Splunk ES will not dedup assets across input files. Let's say you have an IP that has multiple hostnames. Put them in the dns field pipe delimited and only have that IP in one row of one file.

0 Karma
Get Updates on the Splunk Community!

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...

Ready, Set, SOAR: How Utility Apps Can Up Level Your Playbooks!

 WATCH NOW Powering your capabilities has never been so easy with ready-made Splunk® SOAR Utility Apps. Parse ...

DevSecOps: Why You Should Care and How To Get Started

 WATCH NOW In this Tech Talk we will talk about what people mean by DevSecOps and deep dive into the different ...