<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk App for Enterprise Security: How does Identity Management work? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-How-does-Identity-Management/m-p/155584#M621</link>
    <description>&lt;P&gt;@ekost, &lt;BR /&gt;
Could you please explain the point - "The lookups have specific fields and requirements, a .csv structure, and may be populated manually or dynamically. " how to populate the lookup dynamically in a distributed environment, such as AWS?&lt;/P&gt;</description>
    <pubDate>Wed, 20 Nov 2019 09:55:26 GMT</pubDate>
    <dc:creator>gndivya</dc:creator>
    <dc:date>2019-11-20T09:55:26Z</dc:date>
    <item>
      <title>Splunk App for Enterprise Security: How does Identity Management work?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-How-does-Identity-Management/m-p/155576#M613</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;

&lt;P&gt;I was tasked with changing over our Identity management information in splunk since we switched vendors for the information. The person who worked with splunk during the install to set everything up doesn't work here anymore and I don't quite understand how it works. &lt;/P&gt;

&lt;P&gt;In ES I go to Configure-&amp;gt;Identity Management and I see a static asset lookup @ lookup://simple_asset_lookup&lt;BR /&gt;
In ES I go to Configure-&amp;gt;Data Enrichment-&amp;gt;Lists and Lookups-&amp;gt;Assets and it shows assets.csv&lt;/P&gt;

&lt;P&gt;What is the difference between these two and what are they each used for? Right now, they look identical. Do they have to be? &lt;/P&gt;

&lt;P&gt;I have created a search to populate the csv files with data from the new source.&lt;BR /&gt;
Can I populate the csv files with more fields than are currently there?&lt;BR /&gt;
How can I configure what can be put into these csv files and what information is monitored?&lt;/P&gt;

&lt;P&gt;Thanks for any help you can provide.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 20:15:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-How-does-Identity-Management/m-p/155576#M613</guid>
      <dc:creator>smlrwd</dc:creator>
      <dc:date>2020-09-28T20:15:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: How does Identity Management work?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-How-does-Identity-Management/m-p/155577#M614</link>
      <description>&lt;P&gt;Identity Management is a part of the "data onboarding" portion of working with asset and identity information in ES.  Both assets and identities are stored as lookup files. The lookups have specific fields and requirements, a .csv structure, and may be populated manually or dynamically. You may also configure both dynamic and manually updated content, as all configured lookups of a type are loaded and compared, with the resulting merged list being used for Identities reference and search in ES. &lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/ES/3.3.0/Install/IdentityManager"&gt;http://docs.splunk.com/Documentation/ES/3.3.0/Install/IdentityManager&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/ES/3.3.0/Install/IdentityManager#Integrate_new_sources_of_asset_and_identity_information"&gt;http://docs.splunk.com/Documentation/ES/3.3.0/Install/IdentityManager#Integrate_new_sources_of_asset_and_identity_information&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Lists and Lookups is a handy page to review and edit lookup content. &lt;A href="http://docs.splunk.com/Documentation/ES/3.3.0/Install/Applicationprotocolsblacklist#Lists_and_lookups_editor"&gt;http://docs.splunk.com/Documentation/ES/3.3.0/Install/Applicationprotocolsblacklist#Lists_and_lookups_editor&lt;/A&gt;&lt;BR /&gt;
Identities relate to user information such as credentials, roles, email addresses, or sites. &lt;A href="http://docs.splunk.com/Documentation/ES/3.3.0/Install/IdentityManager#Identities_fields"&gt;http://docs.splunk.com/Documentation/ES/3.3.0/Install/IdentityManager#Identities_fields&lt;/A&gt;&lt;BR /&gt;
Assets relate to network devices such as servers, workstations, routers, switches, and other devices. &lt;A href="http://docs.splunk.com/Documentation/ES/3.3.0/Install/IdentityManager#Asset_fields"&gt;http://docs.splunk.com/Documentation/ES/3.3.0/Install/IdentityManager#Asset_fields&lt;/A&gt;&lt;BR /&gt;
For ES to provide a complete perspective, you will need both assets and identities configured.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Can I populate the csv files with more fields than are currently there? Adding additional fields beyond what is defined and required for the lookup won’t prevent the lookup from being merged, but you won’t see the added fields and they won’t be used with the provided ES searches.&lt;/LI&gt;
&lt;LI&gt;How can I configure what can be put into these csv files and what information is monitored? The Identity fields and requirements are defined by ES. If your content is correctly mapped to the fields, you will see the results in the proper context depending upon the dashboard/data you're viewing. If you're looking for customization, I would speak to your Sales Engineer to discuss the use case.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 15 Jun 2015 21:08:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-How-does-Identity-Management/m-p/155577#M614</guid>
      <dc:creator>ekost</dc:creator>
      <dc:date>2015-06-15T21:08:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: How does Identity Management work?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-How-does-Identity-Management/m-p/155578#M615</link>
      <description>&lt;P&gt;This answer really helps, but I have a related follow-up.  Does field order in the custom input file matter?  Assuming you bring in the default required fields (are all fields actually required?), should you just append any extra fields to the end?&lt;/P&gt;

&lt;P&gt;One might wonder, "Why would you bring in any more fields than ES Identity would process?"  We would use the extra fields in the CSV file to augment queries with that information on an as needed basis.  I would suppose that if we really wanted to we could augment the Assets and Identities model with any fields we believed to be additionally important, but I'm not certain how that would impact other functionality in ES.&lt;/P&gt;

&lt;P&gt;Thanks for any additional information you can provide.&lt;/P&gt;</description>
      <pubDate>Sun, 06 Sep 2015 15:07:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-How-does-Identity-Management/m-p/155578#M615</guid>
      <dc:creator>evgnt</dc:creator>
      <dc:date>2015-09-06T15:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: How does Identity Management work?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-How-does-Identity-Management/m-p/155579#M616</link>
      <description>&lt;P&gt;Asset and Identity lookups were designed around a specific set of fields. An asset needs one or more of: ip, mac, nt_host, or dns, An identity needs: identity.  The rest are optional. There's no need to extend the assets and identity fields, just add a new lookup based upon the key field you'd like to enrich. &lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2015 19:00:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-How-does-Identity-Management/m-p/155579#M616</guid>
      <dc:creator>ekost</dc:creator>
      <dc:date>2015-09-08T19:00:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: How does Identity Management work?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-How-does-Identity-Management/m-p/155580#M617</link>
      <description>&lt;P&gt;Actually in our case we would like to add additional fields for our assets/identities so that this will be visible in Asset Investigator once you search on a particular asset. Unfortunately these additional fields are not mappable to the default key fields.&lt;BR /&gt;
I couldn't find documentation on how to add custom fields. Does anyone know how to realize this?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2016 10:55:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-How-does-Identity-Management/m-p/155580#M617</guid>
      <dc:creator>stefan1988</dc:creator>
      <dc:date>2016-10-05T10:55:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: How does Identity Management work?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-How-does-Identity-Management/m-p/155581#M618</link>
      <description>&lt;P&gt;To clarify, would you like to define additional fields to be exposed in the Asset Investigator "Event Panel" when selecting an event, or group of events in an existing swim lane? Or, are you trying to add a new swim lane for Asset Investigator representing events matching a new or custom field?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2016 16:04:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-How-does-Identity-Management/m-p/155581#M618</guid>
      <dc:creator>ekost</dc:creator>
      <dc:date>2016-10-05T16:04:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: How does Identity Management work?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-How-does-Identity-Management/m-p/155582#M619</link>
      <description>&lt;P&gt;I would like to add additional fields in the top panel of Asset Investigator. The top panel is giving information about nt_host, ip, etc. I would like to add a custom field into it. (so this has nothing to do with the swim lane below)&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2016 17:55:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-How-does-Identity-Management/m-p/155582#M619</guid>
      <dc:creator>stefan1988</dc:creator>
      <dc:date>2016-10-05T17:55:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: How does Identity Management work?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-How-does-Identity-Management/m-p/155583#M620</link>
      <description>&lt;P&gt;At the moment, there's no support for adding displayed fields via the UI in ES. I suppose that the page code could be modified, but you'd break 'something' when upgrading to later releases of ES. I suggest you write up the use-case and submit it as an enhancement request. &lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2016 17:15:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-How-does-Identity-Management/m-p/155583#M620</guid>
      <dc:creator>ekost</dc:creator>
      <dc:date>2016-10-06T17:15:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: How does Identity Management work?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-How-does-Identity-Management/m-p/155584#M621</link>
      <description>&lt;P&gt;@ekost, &lt;BR /&gt;
Could you please explain the point - "The lookups have specific fields and requirements, a .csv structure, and may be populated manually or dynamically. " how to populate the lookup dynamically in a distributed environment, such as AWS?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 09:55:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-How-does-Identity-Management/m-p/155584#M621</guid>
      <dc:creator>gndivya</dc:creator>
      <dc:date>2019-11-20T09:55:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: How does Identity Management work?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-How-does-Identity-Management/m-p/155585#M622</link>
      <description>&lt;P&gt;Good day!  Having assets (hosts or other object) in AWS is not unique, but the tool used to track or assign those assets should have a report output that you could extract, format, and load into ES. The documentation around the Asset and Identity &lt;A href="https://docs.splunk.com/Documentation/ES/5.2.0/Admin/Formatassetoridentitylist"&gt;data structure&lt;/A&gt; and &lt;A href="https://docs.splunk.com/Documentation/ES/5.2.0/Admin/Collectandextractassetandidentitydata"&gt;ways to collect that data&lt;/A&gt; is worth a read. &lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 18:06:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-How-does-Identity-Management/m-p/155585#M622</guid>
      <dc:creator>ekost</dc:creator>
      <dc:date>2019-11-20T18:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: How does Identity Management work?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-How-does-Identity-Management/m-p/155586#M623</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;Can I populate the csv files with more fields than are currently there?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;With the release of Enterprise Security 6.0, the Asset and Identity framework supports adding custom fields. See &lt;A href="https://docs.splunk.com/Documentation/ES/6.0.0/Admin/Manageassetsandidentities#Add_a_new_asset_field"&gt;Manage assets and identities in Splunk Enterprise Security&lt;/A&gt; in the Administer Splunk Enterprise Security manual. &lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 18:14:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-How-does-Identity-Management/m-p/155586#M623</guid>
      <dc:creator>ekost</dc:creator>
      <dc:date>2019-11-20T18:14:49Z</dc:date>
    </item>
  </channel>
</rss>

