Collect and extract asset and identity data in Splunk Enterprise Security

Collect and extract your asset and identity data in order to add it to Splunk Enterprise Security. In a Splunk Cloud Platform deployment, work with Splunk Professional Services to design and implement an asset and identity collection solution.

  1. Determine where the asset and identity data in your environment is stored.
  2. Collect and update your asset and identity data automatically to reduce the overhead and maintenance that manual updating requires and improve data integrity.
  • Use Splunk DB Connect or another Splunk platform add-on to connect to an external database or repository.
  • Use scripted inputs to import and format the lists.
  • Use events indexed in the Splunk platform with a search to collect, sort, and export the data to a list.

Suggested collection methods for assets and identities.

Technology Asset or Identity data Collection methods
Active DirectoryBothAD LDAP and a custom search.
Both Splunk Supporting Add-on for Active Directory
BothSecKit Windows Assets Technology Add-on for Splunk Enterprise Security *
LDAPBothAD LDAP and a custom search.
CMDBAssetSplunk DB Connect for integrating with 3rd Party structured data sources, and a custom search.
ServiceNowBoth Splunk Add-on for ServiceNow
Bit9AssetSplunk Add-on for Bit9 and a custom search.
Cisco ISEBothSplunk Add-on for Cisco ISE and a custom search.
Microsoft SCOMAssetSplunk Add-on for Microsoft SCOM and a custom search.
SophosAssetSplunk Add-on for Sophos and a custom search.
Symantec Endpoint ProtectionAssetSplunk Add-on for Symantec Endpoint Protection and a custom search.
Amazon Web Services (AWS)BothCreate Cloud Asset Lookup and Create Cloud Identity Lookup
AzureBothCreate Cloud Asset Lookup and Create Cloud Identity Lookup
Google Cloud PlatformBothCreate Cloud Asset Lookup and Create Cloud Identity Lookup
Configuration Management Database (CMDB)AssetSecKit SA Common tools for populating assets and identities in Enterprise Security and PCI apps *

For more information on custom search commands, see Create custom search commands for apps in Splunk Cloud Platform or Splunk Enterprise

Next step

Format an asset or identity list as a lookup in Splunk Enterprise Security