Splunk Enterprise Security

Splunk Enterprise Security - Expected host not reporting

gmchenry
Explorer

I'm getting hits for "Expected host not responding". I'm using a csv that has a DNS entry as well as an ip address for the host. I searched and there are recent events from the host using the exact match to the dns column entry for the given host.

How exactly does the correlation search and which entries from the assets lookup is it trying to look for or are there certain expected entries or traffic that it is looking for?

I'm still pretty new to ES and any help or guidance is much appreciated.

Thanks!

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...