Splunk Enterprise Security

Asset and Identity management multi valued

inayath_khanin1
Explorer

Identity: 314 assets are currently exceeding the field limits set in the Asset and Identity Management page. Data truncation will occur unless the field limits are increased. Sources: [merge].

0 Karma

lakshman239
SplunkTrust
SplunkTrust

@inayath_khanin1   The above error indicates that during the asset merge process, you have one of the 'key' entries exceeding the multi-value limit setup in the AssetFields page under 'Asset and Identity managent' UI ( you can access  in the ES app via Configure -> Data enrichment -> Asset and Identity managent).  Look at the all the key fields and the multi-value limit. Additionally, you can also check something like this (pick up any field you want to test, e.g. ip which has a mv limit of 6 by default

 

|`assets` | eval my_mvcount = count(ip) | stats count by my_mvcount | where my_mvcount > 3

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Check the lookup contents but you probably hit the issue with some changes after ES upgrade.

In my case I needed to disable merging identities because for some unknown reason it was creating a ridiculous lookup entries

https://docs.splunk.com/Documentation/ES/6.6.0/Admin/Merge

If you have distributed environment, you might not be able to disable merge from webui.  Then you need to fiddle with inputs.conf from SA-IdentityManagement app to disable merge of particular set of assets or identities.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...