<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to set Urgency in a correlation search based on failure count? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-set-Urgency-in-a-correlation-search-based-on-failure/m-p/209227#M1199</link>
    <description>&lt;P&gt;The urgency in a correlation search is calculated by the corr. search severity + the asset/identity priority. &lt;/P&gt;

&lt;P&gt;Is it possible to calculate the urgency based on the count of failures? &lt;/P&gt;

&lt;P&gt;I'm Using Enterprise Security 4.5.1 and I saw you can set Risk Modifiers under "Add New Response Action", but I couldn't find any option to set the urgency based on a field value (i.e. a count of failures).&lt;/P&gt;

&lt;P&gt;Many thanks.&lt;/P&gt;

&lt;P&gt;Kind regards,&lt;BR /&gt;
Stefan&lt;/P&gt;</description>
    <pubDate>Wed, 28 Dec 2016 09:57:10 GMT</pubDate>
    <dc:creator>stefan1988</dc:creator>
    <dc:date>2016-12-28T09:57:10Z</dc:date>
    <item>
      <title>How to set Urgency in a correlation search based on failure count?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-set-Urgency-in-a-correlation-search-based-on-failure/m-p/209227#M1199</link>
      <description>&lt;P&gt;The urgency in a correlation search is calculated by the corr. search severity + the asset/identity priority. &lt;/P&gt;

&lt;P&gt;Is it possible to calculate the urgency based on the count of failures? &lt;/P&gt;

&lt;P&gt;I'm Using Enterprise Security 4.5.1 and I saw you can set Risk Modifiers under "Add New Response Action", but I couldn't find any option to set the urgency based on a field value (i.e. a count of failures).&lt;/P&gt;

&lt;P&gt;Many thanks.&lt;/P&gt;

&lt;P&gt;Kind regards,&lt;BR /&gt;
Stefan&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2016 09:57:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-set-Urgency-in-a-correlation-search-based-on-failure/m-p/209227#M1199</guid>
      <dc:creator>stefan1988</dc:creator>
      <dc:date>2016-12-28T09:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to set Urgency in a correlation search based on failure count?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-set-Urgency-in-a-correlation-search-based-on-failure/m-p/209228#M1200</link>
      <description>&lt;P&gt;You'd want to change the severity of the correlation search according to the number of failures. &lt;/P&gt;

&lt;P&gt;For example, you could append something like this to the end of the correlation search&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; | eval severity=case(failure&amp;gt;100,"critical",failure&amp;gt;50,"high",...
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Then the urgency calculations will take that severity into account, and be adjusted accordingly. &lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2017 01:07:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-set-Urgency-in-a-correlation-search-based-on-failure/m-p/209228#M1200</guid>
      <dc:creator>smoir_splunk</dc:creator>
      <dc:date>2017-01-04T01:07:09Z</dc:date>
    </item>
  </channel>
</rss>

