Hello Team,
Required help regarding below points :
1] how to add entry of the ran search with the fields Host, SourceIP and DestinationIP into lookup table.
2] how to add entry into lookup table from the notable triggered or contributing events of the notable.
Requirement here is that need to create co relation rule from the lookup values which will be taking from previously triggered notables.
Hi @HPACHPANDE ,
you have to save the results of your search in a lookup using the outputlookup command (https://docs.splunk.com/Documentation/Splunk/9.2.0/SearchReference/Outputlookup).
the fields to save in the lookup depends on your search.
Ciao.
Giuseppe