<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What defines an asset priority? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-defines-an-asset-priority/m-p/269641#M11709</link>
    <description>&lt;P&gt;Asset priority , if required specifically, as per your comment is defined in answer I have provided. &lt;/P&gt;</description>
    <pubDate>Sat, 22 Oct 2016 05:23:50 GMT</pubDate>
    <dc:creator>gokadroid</dc:creator>
    <dc:date>2016-10-22T05:23:50Z</dc:date>
    <item>
      <title>What defines an asset priority?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-defines-an-asset-priority/m-p/269637#M11705</link>
      <description>&lt;P&gt;All, &lt;/P&gt;

&lt;P&gt;I am setting up asset center in Splunk ES/PCI. The idea of an Asset priority is sorta vague. Is it left that way on purpose? For me to define? &lt;/P&gt;

&lt;P&gt;"Example: Must be one of unknown, informational, low, medium, high, or critical"&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2016 20:52:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-defines-an-asset-priority/m-p/269637#M11705</guid>
      <dc:creator>daniel333</dc:creator>
      <dc:date>2016-10-21T20:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: What defines an asset priority?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-defines-an-asset-priority/m-p/269638#M11706</link>
      <description>&lt;P&gt;The severity of the event and the priority of the host are combined to generate the urgency of an event.  That is what is built into the system.  Users desktop less important than server, which is less important than a critical app server etc... You get to assign your priorities based on what is important to your environment.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/PCI/3.2.0/User/AssetManagement"&gt;http://docs.splunk.com/Documentation/PCI/3.2.0/User/AssetManagement&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/2056iCE9A1046073FAD34/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2016 21:01:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-defines-an-asset-priority/m-p/269638#M11706</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2016-10-21T21:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: What defines an asset priority?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-defines-an-asset-priority/m-p/269639#M11707</link>
      <description>&lt;P&gt;Hey, thanks for replying. I guess what I am looking for is what defines an asset priority? &lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2016 22:02:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-defines-an-asset-priority/m-p/269639#M11707</guid>
      <dc:creator>daniel333</dc:creator>
      <dc:date>2016-10-21T22:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: What defines an asset priority?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-defines-an-asset-priority/m-p/269640#M11708</link>
      <description>&lt;P&gt;To answer asset priority in simple terms, it means which asset's event will be prioritized if an (similar severity) event occurred at the same time on two assets. Straight from the docs is this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;The priority field (high) is combined with the severity of the search to create the urgency for the notable event.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/PCI/3.2.0/User/AssetManagement#How_asset_fields_are_used"&gt;http://docs.splunk.com/Documentation/PCI/3.2.0/User/AssetManagement#How_asset_fields_are_used&lt;/A&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Prioritization. The same type of events on two different systems may not deserve the same level of attention; a medium severity event against a desktop machine is less urgent than the same issue against an externally facing web-server that processes credit card information. Asset management allows an urgency to be computed based on the priority of hosts and assign higher urgency to high priority assets.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/PCI/3.2.0/User/AssetManagement"&gt;http://docs.splunk.com/Documentation/PCI/3.2.0/User/AssetManagement&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Oct 2016 03:25:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-defines-an-asset-priority/m-p/269640#M11708</guid>
      <dc:creator>gokadroid</dc:creator>
      <dc:date>2016-10-22T03:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: What defines an asset priority?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-defines-an-asset-priority/m-p/269641#M11709</link>
      <description>&lt;P&gt;Asset priority , if required specifically, as per your comment is defined in answer I have provided. &lt;/P&gt;</description>
      <pubDate>Sat, 22 Oct 2016 05:23:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-defines-an-asset-priority/m-p/269641#M11709</guid>
      <dc:creator>gokadroid</dc:creator>
      <dc:date>2016-10-22T05:23:50Z</dc:date>
    </item>
    <item>
      <title>Re: What defines an asset priority?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-defines-an-asset-priority/m-p/269642#M11710</link>
      <description>&lt;P&gt;I have the same/a similar question: How do you change an Asset's priority? I have a bunch of Assets, but they are all medium priority. I want to start changing the priority of some Assets to High and Critical... How do I do this?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Apr 2018 19:29:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-defines-an-asset-priority/m-p/269642#M11710</guid>
      <dc:creator>mshill24</dc:creator>
      <dc:date>2018-04-03T19:29:39Z</dc:date>
    </item>
    <item>
      <title>Re: What defines an asset priority?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-defines-an-asset-priority/m-p/656595#M11711</link>
      <description>&lt;P&gt;You can do that by clicking the Assets and Identity lookups and follow the hyperlink under the source tab. That will redirect it to the contents of the lookup where you can click on the field and edit it.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 02:19:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-defines-an-asset-priority/m-p/656595#M11711</guid>
      <dc:creator>vr2312</dc:creator>
      <dc:date>2023-09-05T02:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: What defines an asset priority?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-defines-an-asset-priority/m-p/658789#M11712</link>
      <description>&lt;P&gt;What about the 3rd dimension, risk? Seems fair to make 3 for urgency.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Sep 2023 18:59:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-defines-an-asset-priority/m-p/658789#M11712</guid>
      <dc:creator>kevin8</dc:creator>
      <dc:date>2023-09-26T18:59:54Z</dc:date>
    </item>
  </channel>
</rss>

