Security

Why is assets_by_cidr.csv lookup file empty?

EssKay
Engager

As I was going through the Asset and Identity Management manual, I couldn't see anything related to how to enrich the two lookup files assets_by_cidr.csv and assets_by_str.csv. For some reason (I couldn't figure out why), the assets_by_str.csv is filled with data and is populating data when running any search. However, nothing is getting fetched to assets_by_cidr.csv, I'm not sure if this is supposed to be filled automatically? and I can't find any configuration that associates where these two CSVs are taking the data from... 

 

I can only see that they're coming from the app SA-IdentityManagement, can someone please help in troubleshooting this? Where are these two lookup table expected to get the data from and how?

Lastly, to give more context, the final purpose it to fulfill the request of data enrichment for this specific use case Detect Large Outbound ICMP Packets...

Labels (1)
Tags (2)
0 Karma

kprior201
Path Finder

These lookups get their information from configured asset lookups within Enterprise Security, as you linked. They're populated automatically  Do your asset lookups have CIDR information included in them? If the string lookup is populating, then you have some kind of assets configured. If you have a dev environment experiencing this problem, you might try enabling the demo_asset_lookup in the Asset and Identity Management page to see if it populates the CIDR one automatically. It has CIDR networks properly built into it.

The best official documentation I came across in my search was https://docs.splunk.com/Documentation/ES/7.3.1/Admin/Howassetandidentitydataprocessed

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...