Splunk Enterprise Security

ES - Correlation Search - Lookup file is not populated

wgawhh5hbnht
Communicator

alt text
3 Correlation Searches stating that previously_seen_users_console_logins.csv isn't populated:

  • Detect new user AWS Console Login
  • Detect AWS Console Login by User from New Region
  • Detect AWS Console Login by User from New Country

The trimmed down & redacted contents of previously_seen_users_console_logins.csv are:

identity,
arn:aws:sts::[account-id]:[assumed-role]/[role-name]/[role-session-name],

I can't find any documentation on how to properly populate this lookup. Any assistance would be greatly appreciated

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...