Hi,
i faced a little issue when i configured " Identities and assets" . After the configuration, the Asset Center and Identity Center dashboard in ES do not work. knowing that :
The assets.csv and identities.csv lookup table under 'Identity Management : OK
These lookup table is in 'Enabled' state : OK
Why this behavior occurred? and how make it to take results from assets.csv and identities.csv.
Please help me in that.
Which version of ES are you using? Is correlation enabled? Correlation is the part that enriches events with your asset and identity data at search time:
https://docs.splunk.com/Documentation/ES/6.4.0/Admin/Correlationsetup