Splunk Enterprise Security

Default account activity is not working (no asset/iden merging)

yusu
Engager

Dear all,

I have a clustering environment (3 Search Heads + Deployer), on the deployer the default account activity is working and the required lookups are there and filled, but on the search cluster member (search heads), its not working and it seems merging is not being done correctly, i tried many thing but with no luck

Here is what it shows on the search heads:

Screenshot 2020-07-15 at 12.41.16.png

 

Please help 😞
Thanks

Tags (2)
0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...