Splunk Enterprise Security

Splunk for Enterprise Security: How to enter two IP addresses for our webserver to show in Asset Investigator?

MaverickT
Communicator

Hi, i am trying to solve issue I encountered with enterprise security. Our company has webserver that is accessible from internal network and from internet. It uses two IP addresses (internal and external). I haven't find the way how to enter both IP addresses for this asset to show them in Asset Investigator. If I enter it pipe separated or dot separated it doesn't help. I have tried with duplicating this asset with different IP address, but it doesn't do the trick as well. Is there any other workaround for this issue?

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

Hi, multi-homed hosts like that require a different technique: http://docs.splunk.com/Documentation/ES/3.1.1/Install/IdentityManager#Define_multi-homed_hosts

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...