Splunk Enterprise Security

Splunk Enterprise Security - How do you add asset fields in new search automatically?

joonoyang
Engager

Hi,

I'm working on adding new data in CIM and putting tags in Communication and network with required fields. Of course, we have proper assets and other data types pull the info well.

I also expect to view asset fields when searching for new data but none are shown. Is there any other way to have assets fields automatically?

Tags: network and communication
Fields:
src_ip
dest_ip
dest_port
src_port
..,

Thanks in advance.

0 Karma

starcher
Influencer

The asset autolookups in ES occur on dest, src, dvc etc not on dest_ip. Make sure you coalesce it field alias your fields like src_ip, src_host into src.

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...