Splunk Enterprise Security

Asset and Identity Management

Threading23
New Member

I need help with adding an asset input stanza for the lookup source. I created a sample lookup that has the proper headers and and set it up to share with the app however I can’t seem to get my lookup to show up within the source drop down on the asset lookup configuration page. Is there a certain way to get the lookup to show up under that dropdown? I am able to see the demo_assets.csv lookup but not the one I configured. I will upload a picture with the steps on the splunk doc where I am stuck.

91B74BDF-DE7D-43EB-9882-AB256FDF393E.png

 

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...