I am new to Splunk and have a question about Asset and Identity data modle. We are on ES 5.3.0. I am trying to load data into Asset and Identify model, need to add some custom fields in addtion to the default fields. I tried to add to the main asset fields, also tried to add to the calculated fields. But when I run |`assets`, it des not show the custom fields I added. Any ideas? Also I did not find in the 5.3.0 document on how to add the custom fields. Only see it in 6.1.1 ES document.
Thank you, richgalloway! Looks like we need to upgrade.
If your problem is resolved, then please click the "Accept as Solution" button to help future readers.