Entity discovery insights

Dynamic views summarize discovered assets, users, IPs, and MACs.

Entity discovery insights provides dynamic, graphical views of all assets, users, IP addresses, and MAC addresses that Splunk Enterprise Security has discovered on your network. Select links in the tables and graphs to view more details about the data. If you prefer a completely tabular view, select View in Entity discovery inventory on any Entity discovery insights tab. For details, see the next article, Entity discovery inventory.

Entity discovery insights includes 4 tabs, each with filters for the relevant insights.

Assets: Displays the number of assets discovered on your network, including breakdowns of assets by type, new assets by type, asset locations, discovery sources, and more. Filters include:

  • All assets

  • Asset trends

  • Cloud assets: Assets discovered from cloud providers with a valid provider field value.

  • Operating systems: Operating systems and versions discovered on your assets. Legacy operating systems match those defined in the Legacy OS enrichment lookup.

Users: Displays the number of users discovered on your network, including breakdowns of users by type, new users by type, user locations, discovery sources, and more. Filters include:

  • All users

  • User trends

  • Default users: Users discovered that match users defined in the default user enrichment lookup.

  • NHI users: Users discovered with a user_type marked in the configuration settings as Non-human (NHI)

  • External users: Users within your organization who have external IP addresses and associated GeoIP locations.

IPs: Displays the number of IP addresses discovered on your network, including breakdowns of IP addresses by type, new IP addresses by type, IP address locations, discovery sources, and more. Filters include:

  • All IPs

  • IP trends

  • Subnets: Subnets discovered from IPs within your organization along with their associated assets and types.

MACs: Displays the number of MAC addresses discovered on your network, including MAC addresses by vendor, new MAC addresses by vendor, MAC address locations, discovery sources, and more. Filters include:

  • All MACs

  • MAC trends

Export a report

To export a report from Exposure Analytics Entity discovery insights, complete the following steps:

  1. Select Analytics then Exposure analytics and then Entity discovery insights.

  2. In any section with a table, select the download icon ( download ).
  3. Enter a name for the file.
  4. Select an Output format, such as JSON.
  5. Select Download.