Is there a suggested collection method for Assets (for Splunk ES), from vCenter?
I see the page "Collect and extract assetandidentitydata in SplunkEnterpriseSecurity", but it does not add...
...EnterpriseSecuritySuite) from etc/shcluster/apps to etc/apps folder Ran the upgrade command – (/opt/splunk/bin/splunk install app ./splunk-enterprise-security_620.spl -update 1) Ran the essinstall command as per the i...
Hi,
I'm trying toadd a new asset list toSplunkEnterpriseSecurity. I can see the lookup in Configuration->Data Enrichment->Identity Management, but it's not showing up when I search f...
I have 2 sourcetype WinHostMon and wineventlog with Splunkadd-on for Microsoft windows. After doing AssetandIdentity configuration in Splunk ES. the lookup file is fine and I can see the results w...
Can any one help me in generating a lookup to dynamically add the Active Directory to the SplunkEnterpriseSecurity - Assets andIdentity list? Had worked out for the the Identity part, but it w...
...ble to investigate artifacts from ES > Incident Review > Selecting the Incident > Action Menu > Investigate Asset Artifacts
but for the life of me, I can't seem to launch SA-I...
I am new toSplunkand have a question about AssetandIdentitydata modle. We are on ES 5.3.0. I am trying to load data into AssetandIdentify model, need toadd some custom fields in add...