Splunk Enterprise Security

Splunk Enterprise Security - How do you add asset fields in new search automatically?

joonoyang
Engager

Hi,

I'm working on adding new data in CIM and putting tags in Communication and network with required fields. Of course, we have proper assets and other data types pull the info well.

I also expect to view asset fields when searching for new data but none are shown. Is there any other way to have assets fields automatically?

Tags: network and communication
Fields:
src_ip
dest_ip
dest_port
src_port
..,

Thanks in advance.

0 Karma

starcher
SplunkTrust
SplunkTrust

The asset autolookups in ES occur on dest, src, dvc etc not on dest_ip. Make sure you coalesce it field alias your fields like src_ip, src_host into src.

0 Karma
Get Updates on the Splunk Community!

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...