I have 2 sourcetype WinHostMon and wineventlog with Splunk add-on for Microsoft windows. After doing Asset and Identity configuration in Splunk ES. the lookup file is fine and I can see the results with the search command:
| inputlookup test_assets2.csv
and Asset Lookup information is also displayed in ES > Security Domains > Identity > Asset Center dashboard. But there is a problem that the enrichment fields for data like dest_asset, dest_asset_id, ... only appear in the WinHostMon sourcetype. Can someone help me pls? Thank you very much!
... View more