All,
So there are situations where folks ask me to "check the logs on everything on subnet 1.2.3.x/25" Rather than by host. Especially with PCI.
Is there a meta data relationship stored in Splunk from the UF and the host name? What about syslog devices?
thanks in advance,
-Daniel
↧