All Apps and Add-ons

Splunk MINT: Why are we not getting the correct device mapping in logs?

Joseph_tukuru
New Member

We have just activated Splunk MINT and noticed in the logs that some IOS devices are coming up as shown below. I am not aware these devices are currently in use and it looks like we are not getting the correct device mapping. Has anyone seen this issue before?

iPhone7,1

iPhone7,2

iPhone8,1

iPhone8,2

iPhone8,4

All_MINT Device device string The mobile device type

Tags (2)
0 Karma

Joseph_tukuru
New Member

the Device field is using the Model Identifier and below shows the mapping for all IOS platforms. So I guess we will have to implement lookup table to match device id.

iPhone7,1 6 Plus";
iPhone7,2 6";
iPhone8,1 6s";

iPhone8,2 6s Plus";
iPhone8,4 SE";

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...