back to day 12
WEEK_2 · DAY_12 · LAB
Lab 12 — Build a Lookup & Macro
Fields, lookups, event types, tags, macros, data models
LAB PROGRESS0/4 steps · 0%
Lab Objectives
- ›Build search-time field extractions
- ›Define event types and tags for normalization
- ›Author macros for reusable SPL
- ›Understand data models and the Common Information Model (CIM)
Lab Instructions
- 1Imagine assets.csv with columns ip, hostname, owner, criticality.
- 2Define an automatic lookup that enriches src_ip in firewall events.
- 3Author a macro `high_value_assets` returning criticality=high hosts.
- 4Use the macro in a search.