<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How does Splunk define and assign urgency in Splunk Enterprise Security? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-does-Splunk-define-and-assign-urgency-in-Splunk-Enterprise/m-p/276835#M2208</link>
    <description>&lt;P&gt;Documentation of the above can be found here: &lt;A href="http://docs.splunk.com/Documentation/ES/4.5.1/User/NotableEvents#How_urgency_is_assigned_to_notable_events"&gt;http://docs.splunk.com/Documentation/ES/4.5.1/User/NotableEvents#How_urgency_is_assigned_to_notable_events&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 11 Dec 2016 16:57:04 GMT</pubDate>
    <dc:creator>rpille_splunk</dc:creator>
    <dc:date>2016-12-11T16:57:04Z</dc:date>
    <item>
      <title>How does Splunk define and assign urgency in Splunk Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-does-Splunk-define-and-assign-urgency-in-Splunk-Enterprise/m-p/276833#M2206</link>
      <description>&lt;P&gt;Hello everyone&lt;/P&gt;

&lt;P&gt;I'm using Splunk Enterprise Security, and at the first sight, I saw urgency which includes: "critical, high, medium, law, info"&lt;/P&gt;

&lt;P&gt;How are these actions divided to these groups? Is there any code behind it as the code in investigations which we could change them manually? &lt;/P&gt;</description>
      <pubDate>Sun, 11 Dec 2016 13:09:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-does-Splunk-define-and-assign-urgency-in-Splunk-Enterprise/m-p/276833#M2206</guid>
      <dc:creator>bettymh</dc:creator>
      <dc:date>2016-12-11T13:09:29Z</dc:date>
    </item>
    <item>
      <title>Re: How does Splunk define and assign urgency in Splunk Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-does-Splunk-define-and-assign-urgency-in-Splunk-Enterprise/m-p/276834#M2207</link>
      <description>&lt;P&gt;hi,&lt;BR /&gt;
Urgency is a combination of&lt;BR /&gt;
1. Priority of the Device  when you build your assets (You can fetch from external sources (eg cmdb) or assign manually. &lt;A href="http://docs.splunk.com/Documentation/ES/4.5.1/User/AssetandIdentityLookupReference"&gt;Doc link&lt;/A&gt;)&lt;BR /&gt;
2. Severity of the use-case  ( You define them when you write the use case/co-relation search)&lt;BR /&gt;
Matrix attached below. Further details of how it can &lt;A href="http://docs.splunk.com/Documentation/ES/latest/User/NotableEvents"&gt;be done etc is show here&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/2230i07FF65A486D8F342/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Dec 2016 15:55:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-does-Splunk-define-and-assign-urgency-in-Splunk-Enterprise/m-p/276834#M2207</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2016-12-11T15:55:31Z</dc:date>
    </item>
    <item>
      <title>Re: How does Splunk define and assign urgency in Splunk Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-does-Splunk-define-and-assign-urgency-in-Splunk-Enterprise/m-p/276835#M2208</link>
      <description>&lt;P&gt;Documentation of the above can be found here: &lt;A href="http://docs.splunk.com/Documentation/ES/4.5.1/User/NotableEvents#How_urgency_is_assigned_to_notable_events"&gt;http://docs.splunk.com/Documentation/ES/4.5.1/User/NotableEvents#How_urgency_is_assigned_to_notable_events&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Dec 2016 16:57:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-does-Splunk-define-and-assign-urgency-in-Splunk-Enterprise/m-p/276835#M2208</guid>
      <dc:creator>rpille_splunk</dc:creator>
      <dc:date>2016-12-11T16:57:04Z</dc:date>
    </item>
    <item>
      <title>Re: How does Splunk define and assign urgency in Splunk Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-does-Splunk-define-and-assign-urgency-in-Splunk-Enterprise/m-p/276836#M2209</link>
      <description>&lt;P&gt;Thank you a lot koshyk (@koshyk)&lt;/P&gt;

&lt;P&gt;but...&lt;BR /&gt;
to clear my meaning, my exact question is how it can understand these priority and severity?&lt;/P&gt;

&lt;P&gt;for example there is a medium risk attack, and splunk understand it as a medium...right? how they do it exactly? &lt;BR /&gt;
or maybe it is critical but they said high, we can change them manually! so there must be something, or some code behind it! to define them as a priority and severity!&lt;/P&gt;</description>
      <pubDate>Mon, 12 Dec 2016 06:24:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-does-Splunk-define-and-assign-urgency-in-Splunk-Enterprise/m-p/276836#M2209</guid>
      <dc:creator>bettymh</dc:creator>
      <dc:date>2016-12-12T06:24:37Z</dc:date>
    </item>
    <item>
      <title>Re: How does Splunk define and assign urgency in Splunk Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-does-Splunk-define-and-assign-urgency-in-Splunk-Enterprise/m-p/276837#M2210</link>
      <description>&lt;P&gt;Will the search command help you? &lt;/P&gt;

&lt;P&gt;From Incident Review dashboard,  click Job -&amp;gt; Inspect Job on the timeline chart&lt;BR /&gt;
A new window opens. Click search.log link at the top&lt;BR /&gt;
Text search for 'SearchParser - AFTER EXPANDING MACROS' and you will see the SPL search command there.&lt;BR /&gt;
Copy the command and run it in the Search and you will see how these data computed&lt;/P&gt;</description>
      <pubDate>Mon, 12 Dec 2016 18:57:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-does-Splunk-define-and-assign-urgency-in-Splunk-Enterprise/m-p/276837#M2210</guid>
      <dc:creator>rxie_splunk</dc:creator>
      <dc:date>2016-12-12T18:57:52Z</dc:date>
    </item>
    <item>
      <title>Re: How does Splunk define and assign urgency in Splunk Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-does-Splunk-define-and-assign-urgency-in-Splunk-Enterprise/m-p/276838#M2211</link>
      <description>&lt;P&gt;You wrote&lt;/P&gt;

&lt;P&gt;"but...&lt;BR /&gt;
to clear my meaning, my exact question is how it can understand these priority and severity?&lt;/P&gt;

&lt;P&gt;for example there is a medium risk attack, and splunk understand it as a medium...right? how they do it exactly? &lt;BR /&gt;
or maybe it is critical but they said high, we can change them manually! so there must be something, or some code behind it! to define them as a priority and severity!"&lt;/P&gt;

&lt;P&gt;Splunk assigns ugency by mapping the assigned severity to the assigned priority of the asset for the various correlation searches.&lt;/P&gt;

&lt;P&gt;It is important to check the chart given in the answer above by koshyk .  I found most of our assets were classified as unknown therefore lowering the urgency of the alert.&lt;/P&gt;

&lt;P&gt;What we did to fix this situation was to change the columns so that ugency matched the assigned severity.  This may not have been the best solution but it solved our issue.  We were then easily able to map the urgency on the incident review dashboard to the expected severity in the correlation search as it no longer considered the asset in making the determination.&lt;/P&gt;

&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Dec 2016 19:19:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-does-Splunk-define-and-assign-urgency-in-Splunk-Enterprise/m-p/276838#M2211</guid>
      <dc:creator>AnthonyTibaldi</dc:creator>
      <dc:date>2016-12-12T19:19:30Z</dc:date>
    </item>
    <item>
      <title>Re: How does Splunk define and assign urgency in Splunk Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-does-Splunk-define-and-assign-urgency-in-Splunk-Enterprise/m-p/276839#M2212</link>
      <description>&lt;P&gt;hi, I've added bit more description to my answer on how to assign them. If you think it is ok, please mark it as answer. cheers&lt;/P&gt;</description>
      <pubDate>Mon, 12 Dec 2016 20:46:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-does-Splunk-define-and-assign-urgency-in-Splunk-Enterprise/m-p/276839#M2212</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2016-12-12T20:46:21Z</dc:date>
    </item>
  </channel>
</rss>

