Lookups and Identity Management Flashcards
1
Q
What is an example of an ES asset?
A
- Server
- Network Devices
- Endpoints
- Databases
- Applications
2
Q
Which columns in the Assets lookup are used to identify an asset in an event?
A
ip, mac, dns, nt_host
3
Q
How does Identity Matching work
A
- ES takes a value from an event’s user, src_user, email, or src_email field and tries to match it to a value in the identities lookup in the following order
1. Identity column (exact match)
2.Email (exact match)
3. Email (alias without domain)
4. Any (disabled by default)
4
Q
A