Splunk Enterprise Security

Splunk Enterprise Security - Expected host not reporting

gmchenry
Explorer

I'm getting hits for "Expected host not responding". I'm using a csv that has a DNS entry as well as an ip address for the host. I searched and there are recent events from the host using the exact match to the dns column entry for the given host.

How exactly does the correlation search and which entries from the assets lookup is it trying to look for or are there certain expected entries or traffic that it is looking for?

I'm still pretty new to ES and any help or guidance is much appreciated.

Thanks!

0 Karma
Get Updates on the Splunk Community!

Monitoring MariaDB and MySQL

In a previous post, we explored monitoring PostgreSQL and general best practices around which metrics to ...

Financial Services Industry Use Cases, ITSI Best Practices, and More New Articles ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Splunk Federated Analytics for Amazon Security Lake

Thursday, November 21, 2024  |  11AM PT / 2PM ET Register Now Join our session to see the technical ...