<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Do I have to disable asset_lookup_by_cidr? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Do-I-have-to-disable-asset-lookup-by-cidr/m-p/458158#M6530</link>
    <description>&lt;P&gt;Thanks for advice. &lt;BR /&gt;
Actually we require enrichment for many sourcetypes and it should be not by cidr but strict by ip. That's what asset_lookup_by_str does. &lt;BR /&gt;
In provided recomendation there's no ability to choose sourcetypes for asset_lookup_by_cidr separately from asset_lookup_by_str (at least for ES ver. 4.7, that we have). &lt;BR /&gt;
Looks like I'll rename output fields for default : LOOKUP-zv-asset_lookup_by_cidr-dest(dvc,src)&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 20:37:39 GMT</pubDate>
    <dc:creator>evelenke</dc:creator>
    <dc:date>2020-09-29T20:37:39Z</dc:date>
    <item>
      <title>Do I have to disable asset_lookup_by_cidr?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Do-I-have-to-disable-asset-lookup-by-cidr/m-p/458156#M6528</link>
      <description>&lt;P&gt;Hi Splunkers,&lt;/P&gt;

&lt;P&gt;In our alerts related to Network domain (IDS, netflow, etc), where in logs there's only IP address available we try to enrich IP addresses with all possible data - src_owner, src_dns etc. &lt;BR /&gt;
src_dns may be correlated from DHCP ACK events or DNS lookup.&lt;BR /&gt;
But for many assets, like mobile or VMs no authentication may be performed and so there are no source to enrich with src_owner value.&lt;/P&gt;

&lt;P&gt;As result owner gets populated from asset_lookup_by_cidr, which is obviously not an appropriate value.&lt;/P&gt;

&lt;P&gt;What is purpose and main use case of this lookup in general?&lt;BR /&gt;
As of now I think it's better to take away at least dns, mac and owner population from this automatic lookup&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:36:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Do-I-have-to-disable-asset-lookup-by-cidr/m-p/458156#M6528</guid>
      <dc:creator>evelenke</dc:creator>
      <dc:date>2020-09-29T20:36:56Z</dc:date>
    </item>
    <item>
      <title>Re: Do I have to disable asset_lookup_by_cidr?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Do-I-have-to-disable-asset-lookup-by-cidr/m-p/458157#M6529</link>
      <description>&lt;P&gt;You could choose to enable it selectively by sourcetype, so that the enrichment only occurs for the sourcetypes where it is valuable. See &lt;A href="https://docs.splunk.com/Documentation/ES/5.1.0/Admin/Configureassetandidentitycorrelation"&gt;https://docs.splunk.com/Documentation/ES/5.1.0/Admin/Configureassetandidentitycorrelation&lt;/A&gt; for the instructions.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jul 2018 17:18:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Do-I-have-to-disable-asset-lookup-by-cidr/m-p/458157#M6529</guid>
      <dc:creator>smoir_splunk</dc:creator>
      <dc:date>2018-07-26T17:18:35Z</dc:date>
    </item>
    <item>
      <title>Re: Do I have to disable asset_lookup_by_cidr?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Do-I-have-to-disable-asset-lookup-by-cidr/m-p/458158#M6530</link>
      <description>&lt;P&gt;Thanks for advice. &lt;BR /&gt;
Actually we require enrichment for many sourcetypes and it should be not by cidr but strict by ip. That's what asset_lookup_by_str does. &lt;BR /&gt;
In provided recomendation there's no ability to choose sourcetypes for asset_lookup_by_cidr separately from asset_lookup_by_str (at least for ES ver. 4.7, that we have). &lt;BR /&gt;
Looks like I'll rename output fields for default : LOOKUP-zv-asset_lookup_by_cidr-dest(dvc,src)&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:37:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Do-I-have-to-disable-asset-lookup-by-cidr/m-p/458158#M6530</guid>
      <dc:creator>evelenke</dc:creator>
      <dc:date>2020-09-29T20:37:39Z</dc:date>
    </item>
  </channel>
</rss>

