Enriching Data – Lookups and Workflows

In this chapter, we will learn how to augment and enrich the data within Splunk. You will learn about:

  • Looking up product code descriptions
  • Flagging suspect IP addresses
  • Creating a session state table
  • Adding hostnames to IP addresses
  • Searching ARIN for a given IP address
  • Triggering a Google search for a given error
  • Generating a chat notification for application errors
  • Looking up inventory from an external database

Get Splunk Operational Intelligence Cookbook - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.