Lookups and Identity Management Flashcards

1
Q

What is an example of an ES asset?

A
  • Server
  • Network Devices
  • Endpoints
  • Databases
  • Applications
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which columns in the Assets lookup are used to identify an asset in an event?

A

ip, mac, dns, nt_host

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How does Identity Matching work

A
  • ES takes a value from an event’s user, src_user, email, or src_email field and tries to match it to a value in the identities lookup in the following order
    1. Identity column (exact match)
    2.Email (exact match)
    3. Email (alias without domain)
    4. Any (disabled by default)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly