![]() When finished reordering, click Save Ranking.Drag and drop the rows of the table into a new order. ![]() To change the rank, do the following under the Identity Lookup Configuration tab: The row at the top of the list takes precedence and the merge process uses that value, as opposed to the row that's ranked second. For example, if you're merging two identities, that both have the priority field value, you need to choose one to take precedence. These are the fields where the rank takes effect. By default, the single value identity fields are as follows: If an identity exists in multiple source files as a single value, or exists multiple times in the same source file, this ranking is the weighted order for merging them. You can rank the order of this list to determine priority for merging identities. Multiple matches are resolved automatically by taking the first match in the table or manually by specifying identity values.Īny new identity list gets added to the bottom of the page by default."Vanya Patel" using the convention ADMIN_first(1)last() is "ADMIN_vpatel"."Rutherford Michael Sullivan" using the convention first(1)middle(1).last() is "rm.sullivan"."Claudia Maria Garcia" using the convention first(3)last(3) is "clagar". ![]() Use the convention of identity_first(n)middle(n)last(n) where identity, first, and last are any columns from the Identities Table, and where n is a number starting with 0. You can identify users by the first few letters of their first name and the first few letters of their last name, based on the columns in the Identities Table. Click + Add a new convention to add a custom convention:.Click Email Short to use the email username.Click Email to use the full email address.The Email convention is turned on by default. When an email convention check box is checked, the email address is used as an additional primary key for identity. (Optional) Configure the conventions that the identity lookup can use to create a common unique key between different identity sources that might otherwise lack the same field.The conventions are extracted from the identity field. You might use this in the case where you have a field in your source file that you don't want to rely on for information.ĭo not use identity in the field exclusion list if you want to use the optional conventions that follow. This excludes the fields and their values from the KV store collections for that particular lookup. In Lookup Field Exclusion List, select fields for the merge process to ignore.In Lookup List Type, identity is selected for you.See Knowledge bundle replication overview in the Splunk Enterprise Distributed Search manual. Changing the default to include asset and identity lookup files in bundle replication might reduce system performance. The merged lookup files are still included in bundle replication to support asset and identity correlation. The asset and identity source lookup files are excluded from bundle replication in an indexer cluster by default. Check the Denylist check box to exclude the lookup file from bundle replication.Enter a detailed description of the contents of this identity list.Enter a descriptive category for this identity list, such as east_coast_employees or strategic_executives.You can provide a name for the identity list stanza, but matching the source name is a good idea.Select the nf definition from the Source drop-down list that corresponds to the CSV source file of assets you uploaded in the prerequisite step.In the New Identity Manager, do the following:.Click the Identity Lookup Configuration tab.From the Splunk ES menu bar, select Configure > Data Enrichment > Asset and Identity Management. ![]() To add a new identity input source, do the following:
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |