Splunk Enterprise Security

Splunk Enterprise Security - Expected host not reporting

gmchenry
Explorer

I'm getting hits for "Expected host not responding". I'm using a csv that has a DNS entry as well as an ip address for the host. I searched and there are recent events from the host using the exact match to the dns column entry for the given host.

How exactly does the correlation search and which entries from the assets lookup is it trying to look for or are there certain expected entries or traffic that it is looking for?

I'm still pretty new to ES and any help or guidance is much appreciated.

Thanks!

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...