Splunk Enterprise Security

Asset Identity Framework subnet does not match ip-subnet relation

melekyav
New Member

We are using Asset Identity Framework for all environment we have.

For asset side, we have CMDB database in the company and we fetch subnet list and description of this subnets. I upload this lookup to the Asset Identity Framework but it did not match ip field from an other lookups and subnets on the new lookup I uploaded.

Also added a new fields on framework, subnet and subnet_category

CIDR Overlay is ON, and our subnet lookup config has CIDR(subnet). 

Lookup structer is that;

subnetprioritypci_domainsubnet_category

xxxx/24  Medium  XXX                Contractor Firm A

How can I merge this subnet category info with the last asset_lookup

 

Thanks.

Labels (1)
0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...