Splunk Enterprise Security

Splunk ES cannot see data from Custom lookup

abhijittikekar
Builder

Splunk Version - 7.2.4.2

Splunk ES Version - 5.3.0

Hi,

I am trying to add a custom lookup within ES to define Category/Priority for certain assets. Followed this article to the letter to create lookup Table & Definitions with correct permissions.
https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Createlookups

Lookup was also formatted as required. I was able to add the Lookup definition under Configure > Data Enrichment > Identity Management but still the new Categories do not show up under any search for the asset nor are they being used by ES for Correlations.

I do see another location Configure > Content > Content Management > Create New Content > Managed Lookup but when I try to add a new Managed Lookup, this new lookup definition is not listed in the drop-down.

Could this be causing ES not to read/merge the data from this new custom lookup? What is the difference between adding lookup under these two locations?

Note: As a test, I added the same data in the built-in assets.csv lookup and now at least ES Asset Center can see the updated Categories for those assets but it still doesn't get added when running Searches/Data Model correlations etc.

Thanks,

~ Abhi

Labels (1)
Tags (2)
0 Karma

Jhunter
Explorer

Hi Abhi,

The difference between the two lookup-addition locations is:

 Configure > Data Enrichment > Identity Management = This is specifically for adding asset/identities lists that adhere to the ES headers (https://docs.splunk.com/Documentation/ES/6.4.0/Admin/FormatassetoridentitylistWhen you add something here, the lookup table gets added to the `asset_sources` macro which is used in the pipeline to generate the final assets list used to automatically correlate the asset data to events

Configure > Content > Content Management > Create New Content > Managed Lookup = This is for general lookup tables that do necessarily have to do with identities/assets management

Ideally, you want to define Category/Priority in your asset generating search (Such as LDAP or SecKit). So in theory you could utilize a lookup command with your special lookup table to define Priority and Category for these assets in the asset generating search. That way you can have one master asset list in Identity Management with the correct Categories and Priority.

Hope this helps, even if a little..

Joey

 

 

 

 

 

 

 

 

 

 

 

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!