Splunk Enterprise Security

Default account activity is not working (no asset/iden merging)

yusu
Engager

Dear all,

I have a clustering environment (3 Search Heads + Deployer), on the deployer the default account activity is working and the required lookups are there and filled, but on the search cluster member (search heads), its not working and it seems merging is not being done correctly, i tried many thing but with no luck

Here is what it shows on the search heads:

Screenshot 2020-07-15 at 12.41.16.png

 

Please help 😞
Thanks

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...