Splunk Enterprise Security

ES Identity: prevent merge for email field

Path Finder

HI all,

in our identity feed there are some instances where different identities are registered with the same email address. ES by default merges using "key" fields and email. I want to disable this behaviour, but I cannot find how to do that. In the documentation it is written "The key field is identity and the default merge convention is email.". Anyone knows how can I change the default merge convention?



Labels (1)
Tags (1)
0 Karma

Splunk Employee
Splunk Employee

Sounds like you could use entity zones: 

(the example is asset, but it's also for identity)

Or change the key to a different field: 

Let me know if that helps. 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...