cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who Me Too'd this topic

Deduplication issue and config document regarding aggregator and output

L1 Bithead

Hi Experts,

 

I’m testing with Splunk but, I got a problem about deduplicate.

I’ve been input different 1000 indicators of IPv4 after deduplicate, there is 750 indicators of IPv4.

below one IP address has a different value but, after deduplicate, I can see only one indicator.

My expectation is that don’t deduplicate or there is multi value for this IP address.

How can I address the issue?

 

Below picture is from minemeld after deduplicate.

그림1.png

 

 

 

below is original indicator from Splunk. as you can see, 172.217.161.78 has a different values. 

 

 

image002.png

 

Also, I’ve searched configuration document for Prototype. I found miner configuration document but, I couldn’t find out prototype for aggregator and output.

https://live.paloaltonetworks.com/t5/MineMeld-Articles/Configuring-nodes/ta-p/77185

 

Does anyone has a document for aggregator and output?

Who Me Too'd this topic