Splunk Enterprise Security

Splunk ES cannot see data from Custom lookup


Splunk Version -

Splunk ES Version - 5.3.0


I am trying to add a custom lookup within ES to define Category/Priority for certain assets. Followed this article to the letter to create lookup Table & Definitions with correct permissions.

Lookup was also formatted as required. I was able to add the Lookup definition under Configure > Data Enrichment > Identity Management but still the new Categories do not show up under any search for the asset nor are they being used by ES for Correlations.

I do see another location Configure > Content > Content Management > Create New Content > Managed Lookup but when I try to add a new Managed Lookup, this new lookup definition is not listed in the drop-down.

Could this be causing ES not to read/merge the data from this new custom lookup? What is the difference between adding lookup under these two locations?

Note: As a test, I added the same data in the built-in assets.csv lookup and now at least ES Asset Center can see the updated Categories for those assets but it still doesn't get added when running Searches/Data Model correlations etc.


~ Abhi

Labels (1)
Tags (2)
0 Karma


Hi Abhi,

The difference between the two lookup-addition locations is:

 Configure > Data Enrichment > Identity Management = This is specifically for adding asset/identities lists that adhere to the ES headers (https://docs.splunk.com/Documentation/ES/6.4.0/Admin/FormatassetoridentitylistWhen you add something here, the lookup table gets added to the `asset_sources` macro which is used in the pipeline to generate the final assets list used to automatically correlate the asset data to events

Configure > Content > Content Management > Create New Content > Managed Lookup = This is for general lookup tables that do necessarily have to do with identities/assets management

Ideally, you want to define Category/Priority in your asset generating search (Such as LDAP or SecKit). So in theory you could utilize a lookup command with your special lookup table to define Priority and Category for these assets in the asset generating search. That way you can have one master asset list in Identity Management with the correct Categories and Priority.

Hope this helps, even if a little..













0 Karma
Get Updates on the Splunk Community!

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...

Splunkbase | Splunk Dashboard Examples App for SimpleXML End of Life

The Splunk Dashboard Examples App for SimpleXML will reach end of support on Dec 19, 2024, after which no new ...

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...