Splunk Enterprise Security

ES - Correlation Search - Lookup file is not populated

wgawhh5hbnht
Communicator

alt text
3 Correlation Searches stating that previously_seen_users_console_logins.csv isn't populated:

  • Detect new user AWS Console Login
  • Detect AWS Console Login by User from New Region
  • Detect AWS Console Login by User from New Country

The trimmed down & redacted contents of previously_seen_users_console_logins.csv are:

identity,
arn:aws:sts::[account-id]:[assumed-role]/[role-name]/[role-session-name],

I can't find any documentation on how to properly populate this lookup. Any assistance would be greatly appreciated

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...