Splunk Enterprise Security - Asset Lookup Fields - superseded
| 0 Votes |
Versioning - This is an older version.
| 1 | Splunk Enterprise Security - Asset Lookup Fields | 4/11/2018 7:25:35 AM |
| 2 | Splunk Enterprise Security - Asset Lookup Fields | 4/11/2018 7:39:23 AM |
| 3 | Splunk Enterprise Security - Asset Lookup Fields | 4/11/2018 7:44:06 AM |
| 4 | Splunk Enterprise Security - Asset Lookup Fields | 4/11/2018 8:04:01 AM |
| 5 | Splunk Enterprise Security - Asset Lookup Fields | 4/11/2018 8:08:06 AM |
| 6 | Splunk Enterprise Security - Asset Lookup Fields | 4/11/2018 9:47:51 AM |
| 7 | Splunk Enterprise Security - Asset Lookup Fields | 4/11/2018 9:56:52 AM |
| 8 | Splunk Enterprise Security - Asset Lookup Fields | 4/19/2018 5:58:43 AM |
| 9 | Splunk Enterprise Security - Asset Lookup Fields | 4/20/2018 8:09:38 AM |
| 10 | Splunk Enterprise Security - Asset Lookup Fields | 5/7/2018 1:15:54 PM |
| 11 | Splunk Enterprise Security - Asset Lookup Fields | 5/7/2018 1:22:25 PM |
Description
Property Details
| 2998583 | |
| Beta - Preliminary testing ready for more | |
| Splunk Enterprise Security - Asset Lookup Fields | |
| BESC | |
| splunk enterprise security assets csv | |
| jimwald on 4/11/2018 7:39:23 AM | |
| jimwald on 4/11/2018 7:39:23 AM | |
| 2489 Views / 0 Downloads | |
* Average over 0 ratings.
** Log In or Register to add your rating.
|
Properties
ip
Period
1 day
| * Results in a true/false |
if ( exists true whose (if true then ( exists ip interfaces of network) else false) ) then concatenation "|" of (addresses whose (it as string != "0.0.0.0") of ip interfaces whose (not loopback of it) of network as string) else nothing
mac
Period
1 day
| * Results in a true/false |
if windows of operating system then concatenation "|" of (mac addresses of adapters of network) else if not windows of operating system then concatenation "|" of ((mac address of it as string) of ip interfaces whose (not loopback of it AND exists mac address of it) of network) else ""
dns
Period
1 day
| * Results in a true/false |
if ( exists true whose (if true then exists dns name else false) ) then dns name else ""
Relevance
Sharing
| Social Media: |

