<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enterprise Security Suite Incident Review - How Do You Edit the Owners List? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-Suite-Incident-Review-How-do-you-edit-the/m-p/199169#M1028</link>
    <description>&lt;P&gt;I belive your users need to be member of the "Security Analyst" (dont remmember the "correct" name) role&lt;/P&gt;

&lt;P&gt;Read the docs, it is described in there how to setup / configure it correctly. &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 17 Jun 2014 11:02:29 GMT</pubDate>
    <dc:creator>lmyrefelt</dc:creator>
    <dc:date>2014-06-17T11:02:29Z</dc:date>
    <item>
      <title>Enterprise Security Suite Incident Review - How do you edit the owners list?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-Suite-Incident-Review-How-do-you-edit-the/m-p/199167#M1026</link>
      <description>&lt;P&gt;How do you control who is in the drop down list of owners, so you can assign a ticket to someone else? It seems to have picked a bunch of random people and not the two people I need in there.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 14:35:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-Suite-Incident-Review-How-do-you-edit-the/m-p/199167#M1026</guid>
      <dc:creator>vaudajordan</dc:creator>
      <dc:date>2022-09-30T14:35:34Z</dc:date>
    </item>
    <item>
      <title>Re: Enterprise Security Suite Incident Review - How Do You Edit the Owners List?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-Suite-Incident-Review-How-do-you-edit-the/m-p/199168#M1027</link>
      <description>&lt;P&gt;Make sure that the users you want to assign notable events to have the "can_own_notable_events" capability. Once you add that, you should see them in the list of people you can assign notable events to in a few minutes.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:52:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-Suite-Incident-Review-How-do-you-edit-the/m-p/199168#M1027</guid>
      <dc:creator>LukeMurphey</dc:creator>
      <dc:date>2020-09-28T16:52:09Z</dc:date>
    </item>
    <item>
      <title>Re: Enterprise Security Suite Incident Review - How Do You Edit the Owners List?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-Suite-Incident-Review-How-do-you-edit-the/m-p/199169#M1028</link>
      <description>&lt;P&gt;I belive your users need to be member of the "Security Analyst" (dont remmember the "correct" name) role&lt;/P&gt;

&lt;P&gt;Read the docs, it is described in there how to setup / configure it correctly. &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2014 11:02:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-Suite-Incident-Review-How-do-you-edit-the/m-p/199169#M1028</guid>
      <dc:creator>lmyrefelt</dc:creator>
      <dc:date>2014-06-17T11:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: Enterprise Security Suite Incident Review - How Do You Edit the Owners List?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-Suite-Incident-Review-How-do-you-edit-the/m-p/615381#M11080</link>
      <description>&lt;P&gt;The problem with this solution is that all Admins have the capability "&lt;SPAN&gt;can_own_notable_events&lt;/SPAN&gt;" and they appear in the list among SOC analysts.&lt;/P&gt;&lt;P&gt;The woraround I found is to disable "es_notable_events" in Lookup definitions page, and edit the kv-store lookup "&lt;SPAN&gt;notable_owners&lt;/SPAN&gt;" by the app "&lt;SPAN&gt;Splunk App for Lookup File Editing".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The impact of this solution is that newly added SOC members need to be added manually to the "notable_owners" lookup.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 12:32:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-Suite-Incident-Review-How-do-you-edit-the/m-p/615381#M11080</guid>
      <dc:creator>aakwah</dc:creator>
      <dc:date>2022-09-30T12:32:22Z</dc:date>
    </item>
  </channel>
</rss>

