Splunk Enterprise Security

How do you send lookup CSV from a forwarder to a search head?

Tylerdygert
Path Finder

Hello,

I am trying to get a lookup CSV file up to my search head from my forwarder. I have created an asset lookup for Enterprise Security on the forwarder using the DB connect app connecting to our SCCM SQL server. Now, the lookup CSV resides on the heavy forwarder where it is useless. I need to get this CSV up to my search head in order to be used as an asset lookup by ES.

Does anyone know how I could accomplish this? Your help is much appreciated.

Note: our Splunk instance has a heavy forwarder (where the file is) that is set to send data to our 2 indexers up in the AWS cloud. These indexers are then searched by our 2 search heads, which are also up in the AWS cloud. The forwarder has no connection to the search head directly.

1 Solution

iandrews_splunk
Splunk Employee
Splunk Employee

If your HF can't connect straight to your SH, you could always ingest the CSV like any other log file.

Then, run a search, from the search head, on the data, create a table in the format you want the lookup to be in, and "outputlookup" the results to a lookup file.

View solution in original post

iandrews_splunk
Splunk Employee
Splunk Employee

If your HF can't connect straight to your SH, you could always ingest the CSV like any other log file.

Then, run a search, from the search head, on the data, create a table in the format you want the lookup to be in, and "outputlookup" the results to a lookup file.

stefan_d
Path Finder

Hi

Is there is perhaps there new capability that allows for this requirement? Ingesting DB data to use for lookups is an option, but I don't think ideal. It consumes license, also additional effort/processing to setup, store and maintain the data in the IDX/C.

I have a similar requirement (and surely it's widely needed) where the DB data source is not reachable to the SH or SHC. All we need is a csv lookup generated from the dbxquery ran on the HF and to forward the object to the SH/C and/or IDX/C.

I suppose one could build a script to achieve this but I rather feel that this could be a helpful feature?

damode
Motivator

I am too in exactly in need for some workaround for this issue. I cant use ldapsearch directly on ES cloud because of this.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...