<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Enterprise Security: How to troubleshoot why the threat_activity index is no longer populating with data? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-troubleshoot-why-the-threat/m-p/216981#M1287</link>
    <description>&lt;P&gt;Not an expert on this app, but I think the summarizing part is defined in alert_actions.conf. The stanza in savedsearches.conf should have a setting like action.&amp;lt;name&amp;gt; = 1 and the corresponding summarization is handled in the alert_actions file. This lets multiple searches reuse the same alert throttling logic.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 14:20:01 GMT</pubDate>
    <dc:creator>cphair</dc:creator>
    <dc:date>2020-09-29T14:20:01Z</dc:date>
    <item>
      <title>Splunk Enterprise Security: How to troubleshoot why the threat_activity index is no longer populating with data?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-troubleshoot-why-the-threat/m-p/216980#M1286</link>
      <description>&lt;P&gt;The threat_activity index isn't populating anymore, and to be honest, I'm not sure how it's supposed to populate.  There's a scheduled search in particular - Threat - Source And Destination Matches - Threat Gen that runs every 30 minutes and I believe it save its results into this index.  However, it recently stopped.  Does anyone know how this search is supposed to populate the threat_activity index?  It doesn't have a summary index configured.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:53:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-troubleshoot-why-the-threat/m-p/216980#M1286</guid>
      <dc:creator>niemesrw</dc:creator>
      <dc:date>2020-09-29T08:53:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: How to troubleshoot why the threat_activity index is no longer populating with data?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-troubleshoot-why-the-threat/m-p/216981#M1287</link>
      <description>&lt;P&gt;Not an expert on this app, but I think the summarizing part is defined in alert_actions.conf. The stanza in savedsearches.conf should have a setting like action.&amp;lt;name&amp;gt; = 1 and the corresponding summarization is handled in the alert_actions file. This lets multiple searches reuse the same alert throttling logic.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:20:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-troubleshoot-why-the-threat/m-p/216981#M1287</guid>
      <dc:creator>cphair</dc:creator>
      <dc:date>2020-09-29T14:20:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: How to troubleshoot why the threat_activity index is no longer populating with data?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-troubleshoot-why-the-threat/m-p/216982#M1288</link>
      <description>&lt;P&gt;A modification to a Gen search in GUI could cause a empty stanza in DA-ESS-ThreatIntelligence/local/savedsearch.conf such as alert.suppress.fields =&lt;/P&gt;

&lt;P&gt;Check your savedsearches.conf in local and remove the wrong options.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2017 09:10:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-troubleshoot-why-the-threat/m-p/216982#M1288</guid>
      <dc:creator>stefan1988</dc:creator>
      <dc:date>2017-09-08T09:10:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: How to troubleshoot why the threat_activity index is no longer populating with data?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-troubleshoot-why-the-threat/m-p/216983#M1289</link>
      <description>&lt;P&gt;If you look at the configuration for "Threat - Source And Destination Matches - Threat Gen" in savedsearches.conf, you should be able to see this "action.threat_activity=1" which is a reference to “alert_actions.conf” in DA-ESS-ThreatIntelligence app which has [threat_activity] stanza. It is a reference to call that alert action&lt;/P&gt;

&lt;P&gt;If you look at this stanza in alert_actions.conf, you can see that it is "summaryindex" ing to threat_activity index (highlighted)&lt;/P&gt;

&lt;P&gt;Please note "summaryindex" is an alias to "collect" command.&lt;/P&gt;

&lt;P&gt;The part where summaryindex command is present in "threat_activity" alert action is given below.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;| summaryindex spool=t uselb=t addtime=t index="$action.threat_activity._name{required=yes}$"&lt;/STRONG&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:37:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-troubleshoot-why-the-threat/m-p/216983#M1289</guid>
      <dc:creator>chethankumarcba</dc:creator>
      <dc:date>2020-09-30T04:37:51Z</dc:date>
    </item>
  </channel>
</rss>

