All,
Is there a lookup table for mac addresses in Splunk ES ? Any formal way or tackling this if not?
MAC addresses are part of the Assets lookup table. See http://docs.splunk.com/Documentation/ES/5.1.1/Admin/Formatassetoridentitylist