Splunk Enterprise Security

Splunk ES Assets and identity setup

splunkcol
Builder

Hi, has anyone worked with Assets and identity from Splunk Enterprise Security?

I already have the App "Splunk Supporting Add-on for Active Directory" installed

From the app I do connection tests and they are successful but when I enter Splunk ES I do not see Assets and Identity information

What should I check?

splunkcol_0-1613051624070.png

 

splunkcol_1-1613051703809.png

 

Labels (1)
0 Karma

splunkcol
Builder

 

Yes, that is what I need but it is not very clear to me, I need support from someone who can guide me since the documentation is not very clear

at this moment I know that I must enter the tab "Data on Boarding"

splunkcol_0-1613062871661.png

but it is not clear to me that I must fill out the form

 

splunkcol_0-1613063505631.png

 

0 Karma

lakshman239
Influencer

One approach you could follow 

1.using the LDAP/AD addon that you have pull all the required fields for asset and identity. On to a temp index 

2. Using the events from temp index, create, format and validate the fields and create required lookups.

3. Update asset/identity inputs/macros to your custom lookups

 

 

 

 

 

 

splunkcol
Builder

Thanks for your answer, because there is no more specific documentation on what are the values ​​that I could put in that form, could you give me an example of how to fill those fields?

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...