Hi Abhi, The difference between the two lookup-addition locations is: Configure > Data Enrichment > Identity Management = This is specifically for adding asset/identities lists that adhere to the ES headers (https://docs.splunk.com/Documentation/ES/6.4.0/Admin/Formatassetoridentitylist) When you add something here, the lookup table gets added to the `asset_sources` macro which is used in the pipeline to generate the final assets list used to automatically correlate the asset data to events Configure > Content > Content Management > Create New Content > Managed Lookup = This is for general lookup tables that do necessarily have to do with identities/assets management Ideally, you want to define Category/Priority in your asset generating search (Such as LDAP or SecKit). So in theory you could utilize a lookup command with your special lookup table to define Priority and Category for these assets in the asset generating search. That way you can have one master asset list in Identity Management with the correct Categories and Priority. Hope this helps, even if a little.. Joey
... View more