<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identies question in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Identies-question/m-p/667680#M11787</link>
    <description>&lt;P&gt;Thanks for your reply!&lt;/P&gt;&lt;P&gt;I guess I should clarify my question though - I can figure out how to generate them, the question is where do I put them? Do I create additional fields in the lookup for the user and somehow splunk will use that field? Make the identify field a multivalue field?&lt;/P&gt;</description>
    <pubDate>Tue, 07 Nov 2023 13:06:18 GMT</pubDate>
    <dc:creator>Niro</dc:creator>
    <dc:date>2023-11-07T13:06:18Z</dc:date>
    <item>
      <title>Identies question</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Identies-question/m-p/667635#M11784</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I've set up an identity lookup using ldapsearch - it creates an identity of "username" that contains various details about the user, including the email address. It works well in identifying the user as `username` and `useremail@domain'.&lt;/P&gt;&lt;P&gt;However I'd like to also have it identify users based on `domain\username` and `username@domain' (which is actually different than `useremail` in our case) since a lot of our logs contain the user field in those formats. What's the best way to do that?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 05:33:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Identies-question/m-p/667635#M11784</guid>
      <dc:creator>Niro</dc:creator>
      <dc:date>2023-11-07T05:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: Identies question</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Identies-question/m-p/667651#M11785</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;There is two options to get those into your lookup.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Get those from you ldap query. This is obviously the best option as then those are absolutely correct. Unfortunately I haven't any suitable AD to look what fields those are and how you could get those. I'm quite trustful that those are there. Just ask from your AD admins and they probably help you.&lt;/LI&gt;&lt;LI&gt;If you have standard how those are created based on other attributes then just regenerate those before you add entry to lookup.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 08:32:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Identies-question/m-p/667651#M11785</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-11-07T08:32:31Z</dc:date>
    </item>
    <item>
      <title>Re: Identies question</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Identies-question/m-p/667680#M11787</link>
      <description>&lt;P&gt;Thanks for your reply!&lt;/P&gt;&lt;P&gt;I guess I should clarify my question though - I can figure out how to generate them, the question is where do I put them? Do I create additional fields in the lookup for the user and somehow splunk will use that field? Make the identify field a multivalue field?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 13:06:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Identies-question/m-p/667680#M11787</guid>
      <dc:creator>Niro</dc:creator>
      <dc:date>2023-11-07T13:06:18Z</dc:date>
    </item>
    <item>
      <title>Re: Identies question</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Identies-question/m-p/667742#M11788</link>
      <description>&lt;P&gt;Probably the easiest way is just add a new fields into the end of your lookup file lines. That way it's easier to use those than use e.g. mvfields.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 20:49:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Identies-question/m-p/667742#M11788</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-11-07T20:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: Identies question</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Identies-question/m-p/667746#M11789</link>
      <description>&lt;P&gt;Thanks!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I did that, but how do I make it use the new field as an identity? IE right now I have the "identity" field which is the samaccountname, and I also see it merged the email address into it when looking at the identity center. However if I add another field (ie domain_identity) it won't use it for identity lookups as far as I can tell. What I did for now (which might be completely the wrong way to do it) is create another identity lookup with the exact same query as the first one (which gets all fields from active directory) but for "identity" I'm adding `domain\username`. That seems to do the trick since it merges identities based on email address (which matches).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm sure I'm missing something very basic here though.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 21:40:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Identies-question/m-p/667746#M11789</guid>
      <dc:creator>Niro</dc:creator>
      <dc:date>2023-11-07T21:40:37Z</dc:date>
    </item>
    <item>
      <title>Re: Identies question</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Identies-question/m-p/667749#M11790</link>
      <description>&lt;P&gt;Have you try to use index_field_list on transforms.conf for CSV based lookup and/or accelerated_fields on collections.conf for kvstore based lookup?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 21:59:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Identies-question/m-p/667749#M11790</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-11-07T21:59:29Z</dc:date>
    </item>
  </channel>
</rss>

