Splunk Search

How to compare data from data model with data from data set?

danutmatei
Explorer

Hello, I have a data model named firewall_logs with firewall data in which the interesting fields are: file_hash, url and source/dest IP.

And I have a dataset named intel_indicators with column named ioc in which I have hashes, IPs, domains and timestamp.

 

What I want to do is to compare the data (hashes, IPs, domains) from ioc column with the fields: file_hash, url, dest_ip. If there is a match, it should be visible.

Any ideea how I can accomplish this ?

 

| tstats summariesonly=t allow_old_summaries=t  ...interesting fields.... from datamodel="firewall_logs"  a

and here I'm stuck

Labels (4)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...