In ES 6.0 assets_by_cidr.csv lookup was migrated to asset_lookup_by_cidr kvstore lookup.
You can populate the KV store table with a dummy entry to remove the message.
Navigate to ES App > Configure > Data Enrichment > Asset and Identity Management
(/en-US/app/SplunkEnterpriseSecuritySuite/ess_entity_management)
On the Asset Lookup Configuration tab, ensure static_assets Status is set to Enable. If not, click the Enable link.
Click the Source simple_asset_lookup and the editor will open in a new window.
Type in 192.168.0.1/30 to the "ip" field and save it.
... View more