The Asset & Identity Framework in Splunk Enterprise Security is the mechanism that transforms raw IP addresses and usernames into business-contextual entities. When a correlation search fires on `dest_ip=10.1.5.22`, ES enriches it with asset data — hostname, owner, criticality, business unit, and whether it's a priority system. This transforms a technical event into a business-relevant incident.
The architect designs how the Asset and Identity tables are populated: from Active Directory (via the SA-ldapsearch add-on), CMDB integrations (ServiceNow, Remedy), network scanners (Qualys, Nessus), or manual CSV imports. The data flows into the `asset_lookup` and `identity_lookup` tables which ES uses at search time for enrichment.
Asset priority drives Urgency calculation in ES. An alert of Severity=Medium on a Priority=Critical server becomes Urgency=High. Without accurate asset data, every alert has the same urgency regardless of the target — the architect's job is to make the system context-aware. CMDB data quality directly determines SOC effectiveness.