# Enable asset correlation

Confirm asset correlation has been setup in Splunk Enterprise Security.

  1. Navigate to Splunk Enterprise Security > Configure > Data Enrichment > Asset and Identity Management.
  2. Switch to the "Correlation Setup" tab.
  3. Either enable for all sourcetypes (Recommended) or selectively by sourcetype.
    • If you choose to enable select sourcetypes, ensure the stash sourcetype is also selected so Notable events will be enriched with asset information.
  4. Save.

# Disable existing asset sources

It may be possible that you have existing Asset Lookups defined. If SentinelOne is widely deployed, existing lookups may no longer be needed.