Splunk Enterprise Security uses an asset and identity management system to correlate asset and identity information with events to provide context and enrich data. There are many docs and discussions on how to populate these A&I in Splunk ES but not many on how to troubleshoot A&I issues and validate the framework. This blog covers various actions as well as steps to assess and validate the A&I framework in Splunk ES.
The post Troubleshooting Guide: Assets & Identities in Splunk Enterprise Security appeared first on TekStream Solutions.