<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Notable Event Urgency issues in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Notable-Event-Urgency-issues/m-p/291275#M2555</link>
    <description>&lt;P&gt;I have setup a few correlated events which currently are showing up in the incident review console as urgency (unknown) if you "Uncheck" all the Urgency levels. I have checked the searches and it has the correct input. I also setup it up so  all three values  eval to "high" (priority,severity,urgency) but it still only fires as high as a "medium" event. Does anyone know what could be causing these events now to show up as high. I have reviewed the articles about how urgency is assigned and the lookup table is fine it actually says it should be set to high but its still not doing it.&lt;/P&gt;</description>
    <pubDate>Mon, 08 Jan 2018 23:06:52 GMT</pubDate>
    <dc:creator>04cjm</dc:creator>
    <dc:date>2018-01-08T23:06:52Z</dc:date>
    <item>
      <title>Notable Event Urgency issues</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Notable-Event-Urgency-issues/m-p/291275#M2555</link>
      <description>&lt;P&gt;I have setup a few correlated events which currently are showing up in the incident review console as urgency (unknown) if you "Uncheck" all the Urgency levels. I have checked the searches and it has the correct input. I also setup it up so  all three values  eval to "high" (priority,severity,urgency) but it still only fires as high as a "medium" event. Does anyone know what could be causing these events now to show up as high. I have reviewed the articles about how urgency is assigned and the lookup table is fine it actually says it should be set to high but its still not doing it.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2018 23:06:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Notable-Event-Urgency-issues/m-p/291275#M2555</guid>
      <dc:creator>04cjm</dc:creator>
      <dc:date>2018-01-08T23:06:52Z</dc:date>
    </item>
    <item>
      <title>Re: Notable Event Urgency issues</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Notable-Event-Urgency-issues/m-p/291276#M2556</link>
      <description>&lt;P&gt;It would be nice if Splunk had a bug tracker where folks could report issues and enhancement requests. The urgency issue has affected us for 4-5 months now, but I have no way to report it to Splunk since 1) I'm not the direct customer, and 2) the customer hasn't added me to their account such that I can report issues (and not for lack of effort on my part for several months).&lt;/P&gt;

&lt;P&gt;I have no idea how the "urgency" is getting set to "unknown". This happens for at least 2 of our correlation searches, but not others. I've read the Splunk docs, which haven't been helpful in this particular case. By all appearances, this is a bug.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 13:54:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Notable-Event-Urgency-issues/m-p/291276#M2556</guid>
      <dc:creator>dsrvern</dc:creator>
      <dc:date>2018-04-24T13:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: Notable Event Urgency issues</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Notable-Event-Urgency-issues/m-p/291277#M2557</link>
      <description>&lt;P&gt;What is the sourcetype of the logs you are searching in the correlation search? &lt;/P&gt;

&lt;P&gt;If they are Windows logs and you have the Windows TA installed, the TA will add a "severity" alias to Windows logs. The severity added by the TA will interfere with the ES severity that determines the Notable urgency. &lt;/P&gt;

&lt;P&gt;The simple fix is to only include the fields you need in the correlation search and make sure not to select the "severity" field. &lt;/P&gt;</description>
      <pubDate>Tue, 06 Nov 2018 15:05:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Notable-Event-Urgency-issues/m-p/291277#M2557</guid>
      <dc:creator>infosecb</dc:creator>
      <dc:date>2018-11-06T15:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: Notable Event Urgency issues</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Notable-Event-Urgency-issues/m-p/291278#M2558</link>
      <description>&lt;P&gt;Due to same names in the ES App and your correlation search the severity values will be overwritten. &lt;/P&gt;

&lt;P&gt;Check if you have any other field as "severity" in the correlation search output. If so then just rename the field to something else. Your problem should be resolved after.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Feb 2019 07:47:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Notable-Event-Urgency-issues/m-p/291278#M2558</guid>
      <dc:creator>jet1276</dc:creator>
      <dc:date>2019-02-15T07:47:23Z</dc:date>
    </item>
  </channel>
</rss>

