# Enable asset correlation

Confirm asset correlation has been setup in Splunk Enterprise Security.

  1. Navigate to Splunk Enterprise Security > Configure > Data Enrichment > Asset and Identity Management.
  2. Switch to the "Correlation Setup" tab.
  3. Either enable for all sourcetypes (Recommended) or selectively by sourcetype.
    • If you choose to enable select sourcetypes, ensure the stash sourcetype is also selected so Notable events will be enriched with asset information.
  4. Save.

# Disable existing asset sources

It may be possible that you have existing Asset Lookups defined. If CrowdStrike is widely deployed in your environment the existing lookups may no longer be needed.