Splunk Enterprise Security

ES Asset and Identity lookups only support a single pipe delimited field...???

responsys_cm
Builder

Here is the link to the documentation page for the ES Asset and Identities lookups:

http://docs.splunk.com/Documentation/ES/5.1.0/Admin/Formatassetoridentitylist#Asset_lookup_header

It states for the ip, mac, nt_host, and dns fields:

"A pipe-delimited list of single IP address or IP ranges. An asset is required to have an entry in the ip, mac, nt_host, or dns fields. Do not use pipe-delimiting for more than one of these fields per asset.

So... if I can only use a pipe delimited field for one of those fields, how am I supposed to track assets that have multiple NICs and thus multiple ips and multiple MAC addresses?

What happens if two fields are defined with pipe delimited values?

Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...