All,
I noticed that asset.csv auto lookup isn't happening with sourcetype=yum. Is there a special way to enable this on Splunk ES? Just a normal lookup?
What search you are running on sourcetype=yum to extract asset information?