<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk issue report: Error in security domain settings in correlation searches and Incident Review page in Security</title>
    <link>https://community.splunk.com/t5/Security/Splunk-issue-report-Error-in-security-domain-settings-in/m-p/693272#M17993</link>
    <description>&lt;P&gt;1. Don't just enable all Correlation Rules. You'll kill your ES installation&lt;/P&gt;&lt;P&gt;2. Try this to find the rule which creates your notables&lt;/P&gt;&lt;PRE&gt;| rest /services/saved/searches&lt;BR /&gt;| search action.notable.param.rule_title="Access - * - Rule"&lt;BR /&gt;| table title action.notable.param.rule_title action.notable.param.security_domain disabled eao:acl.app eai:acl.owner eai:acl.sharing |&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 13 Jul 2024 19:17:19 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2024-07-13T19:17:19Z</dc:date>
    <item>
      <title>Splunk issue report: Error in security domain settings in correlation searches and Incident Review page</title>
      <link>https://community.splunk.com/t5/Security/Splunk-issue-report-Error-in-security-domain-settings-in/m-p/693257#M17988</link>
      <description>&lt;P&gt;While using Splunk ES, we noticed that correlation searches were set&lt;BR /&gt;To an incorrect security field on the Incident Review page. This leads to inaccurate classifications of events&lt;BR /&gt;Security and affects the decision-making process&lt;BR /&gt;&lt;BR /&gt;The first step is to set security Domain = Access&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tuts_0-1720872572968.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31733iF449748F69C79802/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tuts_0-1720872572968.png" alt="tuts_0-1720872572968.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The problem is that instead of being classified as security Domain = Access, it is classified as Theret, and so all cases are classified as Theret&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tuts_1-1720872610012.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31734i74644E9960DB5606/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tuts_1-1720872610012.png" alt="tuts_1-1720872610012.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;This causes us a problem with the values ​​not appearing on the Security Posture page&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tuts_2-1720872678035.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31735iEFAD613EEA97BE24/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tuts_2-1720872678035.png" alt="tuts_2-1720872678035.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jul 2024 12:15:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-issue-report-Error-in-security-domain-settings-in/m-p/693257#M17988</guid>
      <dc:creator>tuts</dc:creator>
      <dc:date>2024-07-13T12:15:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk issue report: Error in security domain settings in correlation searches and Incident Review page</title>
      <link>https://community.splunk.com/t5/Security/Splunk-issue-report-Error-in-security-domain-settings-in/m-p/693259#M17989</link>
      <description>&lt;P&gt;1. Maybe someone tampered with your installation. This is from my lab with default settings:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PickleRick_0-1720878447531.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31736i4C7552FFD1A7F7F7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="PickleRick_0-1720878447531.png" alt="PickleRick_0-1720878447531.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;2. Anyway, even if there was an error, the proper channel to report it is to create a Support case. This is a community-driven forum, not a support channel&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jul 2024 13:48:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-issue-report-Error-in-security-domain-settings-in/m-p/693259#M17989</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-07-13T13:48:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk issue report: Error in security domain settings in correlation searches and Incident Review page</title>
      <link>https://community.splunk.com/t5/Security/Splunk-issue-report-Error-in-security-domain-settings-in/m-p/693262#M17990</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tuts_0-1720881668246.jpeg" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31737iAD8CCF6AAF2BA62B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tuts_0-1720881668246.jpeg" alt="tuts_0-1720881668246.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have the same settings, it categorizes all...&lt;BR /&gt;Correlation with the value Threat&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jul 2024 14:43:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-issue-report-Error-in-security-domain-settings-in/m-p/693262#M17990</guid>
      <dc:creator>tuts</dc:creator>
      <dc:date>2024-07-13T14:43:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk issue report: Error in security domain settings in correlation searches and Incident Review page</title>
      <link>https://community.splunk.com/t5/Security/Splunk-issue-report-Error-in-security-domain-settings-in/m-p/693265#M17991</link>
      <description>&lt;P&gt;I'm tempted to say you're looking at a wrong correlation search. The one we're both looking into is a standard search defined in SA-AccessProtection called "Excessive Failed Logins", right?&lt;/P&gt;&lt;P&gt;And it should produce a notable with a title "Excessive Failed Logins". But your notables have a title "Access - login splunk - Rule". It is most probably something created in your environment (even more so because splunk is spelled with lowercase "S" so it's definitely not something provided by Splunk.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jul 2024 17:15:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-issue-report-Error-in-security-domain-settings-in/m-p/693265#M17991</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-07-13T17:15:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk issue report: Error in security domain settings in correlation searches and Incident Review page</title>
      <link>https://community.splunk.com/t5/Security/Splunk-issue-report-Error-in-security-domain-settings-in/m-p/693268#M17992</link>
      <description>&lt;P class="lia-align-right"&gt;Yes, exactly, this is what I am surprised about, why does it add Access - login splunk - Rule although I did not modify the address is there a solution to this problem for me and I will be&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-07-13 21_14_12-Content Management _ Splunk and 21 more pages - Profile 1 - Microsoft​ Edge.jpg" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31738i34AFAE10C7B2B98A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2024-07-13 21_14_12-Content Management _ Splunk and 21 more pages - Profile 1 - Microsoft​ Edge.jpg" alt="2024-07-13 21_14_12-Content Management _ Splunk and 21 more pages - Profile 1 - Microsoft​ Edge.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-07-13 21_15_17-Content Management _ Splunk and 21 more pages - Profile 1 - Microsoft​ Edge.jpg" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31739i47FC82EF770E2795/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2024-07-13 21_15_17-Content Management _ Splunk and 21 more pages - Profile 1 - Microsoft​ Edge.jpg" alt="2024-07-13 21_15_17-Content Management _ Splunk and 21 more pages - Profile 1 - Microsoft​ Edge.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I activated every rule but still the same problem all the results categorize Threat&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt; &lt;/P&gt;&lt;P class="lia-align-right"&gt;grateful to you&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jul 2024 18:17:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-issue-report-Error-in-security-domain-settings-in/m-p/693268#M17992</guid>
      <dc:creator>tuts</dc:creator>
      <dc:date>2024-07-13T18:17:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk issue report: Error in security domain settings in correlation searches and Incident Review page</title>
      <link>https://community.splunk.com/t5/Security/Splunk-issue-report-Error-in-security-domain-settings-in/m-p/693272#M17993</link>
      <description>&lt;P&gt;1. Don't just enable all Correlation Rules. You'll kill your ES installation&lt;/P&gt;&lt;P&gt;2. Try this to find the rule which creates your notables&lt;/P&gt;&lt;PRE&gt;| rest /services/saved/searches&lt;BR /&gt;| search action.notable.param.rule_title="Access - * - Rule"&lt;BR /&gt;| table title action.notable.param.rule_title action.notable.param.security_domain disabled eao:acl.app eai:acl.owner eai:acl.sharing |&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jul 2024 19:17:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-issue-report-Error-in-security-domain-settings-in/m-p/693272#M17993</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-07-13T19:17:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk issue report: Error in security domain settings in correlation searches and Incident Review page</title>
      <link>https://community.splunk.com/t5/Security/Splunk-issue-report-Error-in-security-domain-settings-in/m-p/693276#M17994</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-07-13 23_07_29-Search _ Splunk 9.2.1 and 15 more pages - Profile 1 - Microsoft​ Edge.jpg" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31742i2BF4B7B890CF571A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2024-07-13 23_07_29-Search _ Splunk 9.2.1 and 15 more pages - Profile 1 - Microsoft​ Edge.jpg" alt="2024-07-13 23_07_29-Search _ Splunk 9.2.1 and 15 more pages - Profile 1 - Microsoft​ Edge.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; No results found&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jul 2024 20:08:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-issue-report-Error-in-security-domain-settings-in/m-p/693276#M17994</guid>
      <dc:creator>tuts</dc:creator>
      <dc:date>2024-07-13T20:08:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk issue report: Error in security domain settings in correlation searches and Incident Review page</title>
      <link>https://community.splunk.com/t5/Security/Splunk-issue-report-Error-in-security-domain-settings-in/m-p/693277#M17995</link>
      <description>&lt;P&gt;Try&lt;/P&gt;&lt;PRE&gt;/serviceNS/-/-/&lt;/PRE&gt;&lt;P&gt;instead of&lt;/P&gt;&lt;PRE&gt;/services/&lt;/PRE&gt;</description>
      <pubDate>Sat, 13 Jul 2024 22:44:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-issue-report-Error-in-security-domain-settings-in/m-p/693277#M17995</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-07-13T22:44:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk issue report: Error in security domain settings in correlation searches and Incident Review page</title>
      <link>https://community.splunk.com/t5/Security/Splunk-issue-report-Error-in-security-domain-settings-in/m-p/693280#M17996</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-07-14 08_49_28-Search _ Splunk 9.2.1 and 17 more pages - Profile 1 - Microsoft​ Edge.jpg" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31743i0716537EF000C91F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2024-07-14 08_49_28-Search _ Splunk 9.2.1 and 17 more pages - Profile 1 - Microsoft​ Edge.jpg" alt="2024-07-14 08_49_28-Search _ Splunk 9.2.1 and 17 more pages - Profile 1 - Microsoft​ Edge.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; No results found&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jul 2024 05:51:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-issue-report-Error-in-security-domain-settings-in/m-p/693280#M17996</guid>
      <dc:creator>tuts</dc:creator>
      <dc:date>2024-07-14T05:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk issue report: Error in security domain settings in correlation searches and Incident Review page</title>
      <link>https://community.splunk.com/t5/Security/Splunk-issue-report-Error-in-security-domain-settings-in/m-p/693283#M17997</link>
      <description>&lt;P&gt;Sorry, my typo. It's servicesNS (plural).&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jul 2024 09:14:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-issue-report-Error-in-security-domain-settings-in/m-p/693283#M17997</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-07-14T09:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk issue report: Error in security domain settings in correlation searches and Incident Review page</title>
      <link>https://community.splunk.com/t5/Security/Splunk-issue-report-Error-in-security-domain-settings-in/m-p/693297#M17998</link>
      <description>&lt;P&gt;What should I do now to solve the problem&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jul 2024 17:10:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-issue-report-Error-in-security-domain-settings-in/m-p/693297#M17998</guid>
      <dc:creator>tuts</dc:creator>
      <dc:date>2024-07-14T17:10:59Z</dc:date>
    </item>
  </channel>
</rss>

