- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SplunkES -Data Enrichment - Asset and Identity Management- How does the content update work?
restinlinux
Explorer
11-07-2022
06:17 AM
The changes of the data source are not immediately reflected and some old information remains for several minutes.
How the content updates works? cron ? or Or is each data source combined and returned with each inputlookup reference?
Or this depend on the environment use.. Clustering?
e.g. whether synchronization between search heads takes time and a time lag exists in the reflection of the results.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
11-07-2022
12:29 PM
You are correct. Changes to assets and identities do not take effect immediately. A set of saved search runs periodically to refresh the lists. You can find the relevant searches by looking for "Asset * - Lookup Gen" and "Identity * - Lookup Gen"
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
