Hi ,
my goal is to detect if there is any matches with my custom Domain_IOC.csv list and display additional column for the note.
Domain_IOC.csv list includes two columns
Domain and ioc_note (example picture attached of lookup table)
I want the output to be if there was matches with domain is to include the ioc_note column as well.
Current Query I have (Which provides me the matches with domain but doesn't include ioc_note column)
index=dns sourcetype="dnslog" [|inputlookup Domain_IOC.csv |fields Domain]
| eval Date=strftime(_time, "%Y-%m-%d %H:%M:%S")
| stats values(Domain) as IOC by Date,host,Account,IP,Action
For your kind support.
... View more