⛏️ Get Splunky!
Lv.1Intern
0 XP
0
Home Map Stats Drill Board Log In
Back to Floor
Data Architecture • Room 5

Asset & Identity Framework in ES

The Asset & Identity Framework in Splunk Enterprise Security is the mechanism that transforms raw IP addresses and usernames into business-contextual entities. When a correlation search fires on `dest_ip=10.1.5.22`, ES enriches it with asset data — hostname, owner, criticality, business unit, and whether it's a priority system. This transforms a technical event into a business-relevant incident.

The architect designs how the Asset and Identity tables are populated: from Active Directory (via the SA-ldapsearch add-on), CMDB integrations (ServiceNow, Remedy), network scanners (Qualys, Nessus), or manual CSV imports. The data flows into the `asset_lookup` and `identity_lookup` tables which ES uses at search time for enrichment.

Asset priority drives Urgency calculation in ES. An alert of Severity=Medium on a Priority=Critical server becomes Urgency=High. Without accurate asset data, every alert has the same urgency regardless of the target — the architect's job is to make the system context-aware. CMDB data quality directly determines SOC effectiveness.

Validate your CMDB import regularly. An out-of-date asset table where decommissioned servers still show as Priority=Critical will generate high-urgency false positives and erode analyst trust. Design an automated validation and refresh pipeline.

Knowledge Check

Prove your understanding to clear the room (Rewards XP)
Complete the ES Urgency calculation logic:
Urgency = Correlation Search combined with Asset/Identity