Here is my question.
List A has 150 hosts. Imported 3 weeks ago. Mostly static addresses, some dynamic
List B has 300 hosts. Imported 1 week ago. Some static, most dynamic
How does splunk handle the following:
1) If there is an asset in List A but not List B, does Splunk remove the asset or does it keep it?
2) If there is an updated DNS or IP address, does it create two entries for that specific assets?
-Specifically if there is a host with an updated dynamic IP address, does it keep both entries?
-If there is an old IP address in Splunk that is reused and now becomes a static IP address for a server, what DNS would Splunk show?
3) If there are assets in List A and List B, does it duplicate the asset entry?
... View more