Splunk - Create and Update Assets
Splunk - Create and Update Assets creates and/or updates assets in Splunk for:
- Assets returned by the selected query or assets selected on the relevant asset page.
Depending on the action selected, assets not in Splunk will be created and existing Splunk assets will be updated.
See Creating Enforcement Sets to learn more about adding Enforcement Actions to Enforcement Sets.
Note
- Not all asset types are supported for all Enforcement Actions.
- See Actions supported for Activity Logs, Adapters Fetch History, and Asset Investigation modules.
- See Actions supported for Aggregated Security Findings.
- See Actions supported for Software.
Required Fields
-
Compute Node - The Axonius node to use when connecting to the specified host. For more details, see Working with Axonius Compute Nodes.
- Action name - The name of this Enforcement Action. The system sets a default name. You can change the name.
- Configure Dynamic Values (optional) - Toggle on to enter a Dynamic Value statement. See Creating Enforcement Action Dynamic Value Statements to learn more about Dynamic Value statement syntax.
-
Use stored credentials from Splunk adapter - Select this option to choose which Splunk connected adapter credentials to use.
-
When you select this option, the Select Adapter Connection drop-down becomes available. Select the adapter connection to use for this Enforcement Action.
Note
To use this option, you must successfully configure a Splunk adapter connection.
-
Additional Fields
These fields are optional.
Updated 13 days ago
