<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Risk Score, Risk Event and Risk Object is not showing in the notable event. in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-aren-t-Risk-Score-Risk-Event-and-Risk-Object-showing-in-the/m-p/613208#M11031</link>
    <description>&lt;P&gt;Hi. Yes, I see the confusion. The fields you add under the&amp;nbsp;&lt;SPAN&gt;response action "Risk Analysis" are not added the the notable event itself (index=notable), they are added to the risk event (index=risk). These risk events are used for Risk-Based Alerting, among other things.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you want the "user" and "app" fields to be added to the notable event, just make sure these fields are present in the final output of your correlation search, and you shoud see them in the incident.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 15 Sep 2022 11:14:46 GMT</pubDate>
    <dc:creator>hettervik</dc:creator>
    <dc:date>2022-09-15T11:14:46Z</dc:date>
    <item>
      <title>Why aren't Risk Score, Risk Event and Risk Object showing in the notable event?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-aren-t-Risk-Score-Risk-Event-and-Risk-Object-showing-in-the/m-p/612197#M11021</link>
      <description>&lt;P&gt;Hi peeps,&lt;/P&gt;
&lt;P&gt;We were fine tuning the Notable Event, and there were fields that were not showing any values. Those fields are the Risk Score, Risk Event and Risk Object. We have configure the value under the Risk Analysis Tab.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WhatsApp Image 2022-09-07 at 15.00.21.jpeg" style="width: 602px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/21349iEDF32F6BE3DF64CA/image-dimensions/602x250?v=v2" width="602" height="250" role="button" title="WhatsApp Image 2022-09-07 at 15.00.21.jpeg" alt="WhatsApp Image 2022-09-07 at 15.00.21.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WhatsApp Image 2022-09-07 at 15.01.06.jpeg" style="width: 403px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/21350i9C979DA4697A7772/image-dimensions/403x308?v=v2" width="403" height="308" role="button" title="WhatsApp Image 2022-09-07 at 15.01.06.jpeg" alt="WhatsApp Image 2022-09-07 at 15.01.06.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Please assist us on this. Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2022 14:31:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-aren-t-Risk-Score-Risk-Event-and-Risk-Object-showing-in-the/m-p/612197#M11021</guid>
      <dc:creator>syazwani</dc:creator>
      <dc:date>2022-09-15T14:31:00Z</dc:date>
    </item>
    <item>
      <title>Re: Risk Score, Risk Event and Risk Object is not showing in the notable event.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-aren-t-Risk-Score-Risk-Event-and-Risk-Object-showing-in-the/m-p/613208#M11031</link>
      <description>&lt;P&gt;Hi. Yes, I see the confusion. The fields you add under the&amp;nbsp;&lt;SPAN&gt;response action "Risk Analysis" are not added the the notable event itself (index=notable), they are added to the risk event (index=risk). These risk events are used for Risk-Based Alerting, among other things.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you want the "user" and "app" fields to be added to the notable event, just make sure these fields are present in the final output of your correlation search, and you shoud see them in the incident.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2022 11:14:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-aren-t-Risk-Score-Risk-Event-and-Risk-Object-showing-in-the/m-p/613208#M11031</guid>
      <dc:creator>hettervik</dc:creator>
      <dc:date>2022-09-15T11:14:46Z</dc:date>
    </item>
    <item>
      <title>Re: Why aren't Risk Score, Risk Event and Risk Object showing in the notable event?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-aren-t-Risk-Score-Risk-Event-and-Risk-Object-showing-in-the/m-p/658437#M11703</link>
      <description>&lt;P&gt;Have you found a solution for this? I'm experiencing the same thing, and I made sure that the fields we provided in the Risk Analysis Adaptive response Action is a valid field that is being presented in the correlation search results. In fact, I'm using the same fields as variables in the title of the notable event. But nothing is populating in Incident review for Risk Score, Risk Event, and Risk Object.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2023 15:11:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-aren-t-Risk-Score-Risk-Event-and-Risk-Object-showing-in-the/m-p/658437#M11703</guid>
      <dc:creator>travis_lelle</dc:creator>
      <dc:date>2023-09-22T15:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: Why aren't Risk Score, Risk Event and Risk Object showing in the notable event?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-aren-t-Risk-Score-Risk-Event-and-Risk-Object-showing-in-the/m-p/676965#M11911</link>
      <description>&lt;P&gt;Hey so did you find the solution? We stacked with the same issue and seams no one knows how to fix it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 13:14:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-aren-t-Risk-Score-Risk-Event-and-Risk-Object-showing-in-the/m-p/676965#M11911</guid>
      <dc:creator>roberto_baggio</dc:creator>
      <dc:date>2024-02-08T13:14:09Z</dc:date>
    </item>
  </channel>
</rss>

