<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to enrich notable events in ES? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-enrich-notable-events-in-ES/m-p/660401#M11743</link>
    <description>&lt;P&gt;Have you consulted resources like these?&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://lantern.splunk.com/Security/UCE/Prioritized_Actions/Threat_intelligence/Using_threat_intelligence_in_Splunk_Enterprise_Security?_ga=2.158226682.1710119261.1697025883-338010800.1672937249&amp;amp;_gl=1%2Aigs7z5%2A_ga%2AMzM4MDEwODAwLjE2NzI5MzcyNDk.%2A_ga_GS7YF8S63Y%2AMTY5NzAzMzQwMS45NS4xLjE2OTcwMzM5MDkuNDYuMC4w%2A_ga_5EPM2P39FV%2AMTY5NzAzMzQwMS4xMjMuMS4xNjk3MDMzOTIxLjAuMC4w" target="_blank" rel="noopener"&gt;Using threat intelligence in Splunk Enterprise Security&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://lantern.splunk.com/Security/Getting_Started/Unified_App_for_ES%3A_Enrich_and_submit_notable_events_-_Splunk_Intelligence_Management_(TruSTAR)" target="_blank" rel="noopener"&gt;Unified App for ES: Enrich and submit notable events - Splunk Intel Management (TruSTAR)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Oct 2023 14:21:57 GMT</pubDate>
    <dc:creator>JohnEGones</dc:creator>
    <dc:date>2023-10-11T14:21:57Z</dc:date>
    <item>
      <title>How to enrich notable events in ES?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-enrich-notable-events-in-ES/m-p/659699#M11730</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;We are wanting to enrich events as they become notables in ES before they are sent onto Mission control. Thoughts being, enrich the event via some sort of search ( all the data will be in splunk already) to add , DNS, DHCP, Threat intel and some endpoint data.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Is it possible to have a search run for the notable index to gather information from other indexes and add them to the notable event?&amp;nbsp; If so I would love to discuss.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2023 21:44:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-enrich-notable-events-in-ES/m-p/659699#M11730</guid>
      <dc:creator>cjharmening</dc:creator>
      <dc:date>2023-10-04T21:44:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to enrich notable events in ES?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-enrich-notable-events-in-ES/m-p/660401#M11743</link>
      <description>&lt;P&gt;Have you consulted resources like these?&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://lantern.splunk.com/Security/UCE/Prioritized_Actions/Threat_intelligence/Using_threat_intelligence_in_Splunk_Enterprise_Security?_ga=2.158226682.1710119261.1697025883-338010800.1672937249&amp;amp;_gl=1%2Aigs7z5%2A_ga%2AMzM4MDEwODAwLjE2NzI5MzcyNDk.%2A_ga_GS7YF8S63Y%2AMTY5NzAzMzQwMS45NS4xLjE2OTcwMzM5MDkuNDYuMC4w%2A_ga_5EPM2P39FV%2AMTY5NzAzMzQwMS4xMjMuMS4xNjk3MDMzOTIxLjAuMC4w" target="_blank" rel="noopener"&gt;Using threat intelligence in Splunk Enterprise Security&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://lantern.splunk.com/Security/Getting_Started/Unified_App_for_ES%3A_Enrich_and_submit_notable_events_-_Splunk_Intelligence_Management_(TruSTAR)" target="_blank" rel="noopener"&gt;Unified App for ES: Enrich and submit notable events - Splunk Intel Management (TruSTAR)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 14:21:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-enrich-notable-events-in-ES/m-p/660401#M11743</guid>
      <dc:creator>JohnEGones</dc:creator>
      <dc:date>2023-10-11T14:21:57Z</dc:date>
    </item>
  </channel>
</rss>

