<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Add Adaptive Response fields to Notable Event in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Add-Adaptive-Response-fields-to-Notable-Event/m-p/439174#M5860</link>
    <description>&lt;P&gt;I've done quite a bit of research on this top and I've found &lt;A href="https://answers.splunk.com/answers/481995/splunk-enterprise-security-how-to-add-fields-to-no.html?utm_source=typeahead&amp;amp;utm_medium=newquestion&amp;amp;utm_campaign=no_votes_sort_relev"&gt;this&lt;/A&gt; post from a few years ago which references George Starcher's &lt;A href="http://www.georgestarcher.com/splunk-enterprise-security-enhancing-incident-review/"&gt;blog&lt;/A&gt; post about it. I've gotten quite a ways into it but I've ran into an issue using my new search macro in the "Incident Review - Main" search. &lt;/P&gt;

&lt;P&gt;Below are the steps I've completed so far.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Created a VirusTotal Adaptive Response Action that auto queries the domain of the notable event. This is working very well and I can get the results if I click on my VT notable event.&lt;/LI&gt;
&lt;LI&gt;I created a vtpositives(1) macro that looks like this (I know it's not best practices for some of my search items, this is just a dev system) search index=_* OR index=* VirusTotal "queried url" $query$ source!=audittrail | table positives&lt;/LI&gt;
&lt;LI&gt;When I run the macro from a search and input the URL, it shows the number of positive hits that VirusTotal shows up, which is the field I want to show up in additional fields under the notable event.&lt;/LI&gt;
&lt;LI&gt;I modified the "Incident Review - Main" search to add &lt;CODE&gt;vtpositives(1)&lt;/CODE&gt; right before the &lt;CODE&gt;risk_correlation&lt;/CODE&gt; field that is currently last. I have tried both with the (1) and without it. I know that the "query" field populates correctly within the notable event and the VirusTotal results.&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Once I go to click on the notable events, the page is 100% blank. It does not like my macro at all and prevents any search results from coming up. So my real question is how do I get the positives field out of my search macro and into the notable event?&lt;/P&gt;

&lt;P&gt;For some reason my URLs are not working above so here they are.&lt;BR /&gt;
- &lt;A href="https://answers.splunk.com/answers/481995/splunk-enterprise-security-how-to-add-fields-to-no.html?utm_source=typeahead&amp;amp;utm_medium=newquestion&amp;amp;utm_campaign=no_votes_sort_relev"&gt;https://answers.splunk.com/answers/481995/splunk-enterprise-security-how-to-add-fields-to-no.html?utm_source=typeahead&amp;amp;utm_medium=newquestion&amp;amp;utm_campaign=no_votes_sort_relev&lt;/A&gt;&lt;BR /&gt;
- &lt;A href="http://www.georgestarcher.com/splunk-enterprise-security-enhancing-incident-review/"&gt;http://www.georgestarcher.com/splunk-enterprise-security-enhancing-incident-review/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 31 Jan 2019 20:18:27 GMT</pubDate>
    <dc:creator>ericl42</dc:creator>
    <dc:date>2019-01-31T20:18:27Z</dc:date>
    <item>
      <title>Add Adaptive Response fields to Notable Event</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Add-Adaptive-Response-fields-to-Notable-Event/m-p/439174#M5860</link>
      <description>&lt;P&gt;I've done quite a bit of research on this top and I've found &lt;A href="https://answers.splunk.com/answers/481995/splunk-enterprise-security-how-to-add-fields-to-no.html?utm_source=typeahead&amp;amp;utm_medium=newquestion&amp;amp;utm_campaign=no_votes_sort_relev"&gt;this&lt;/A&gt; post from a few years ago which references George Starcher's &lt;A href="http://www.georgestarcher.com/splunk-enterprise-security-enhancing-incident-review/"&gt;blog&lt;/A&gt; post about it. I've gotten quite a ways into it but I've ran into an issue using my new search macro in the "Incident Review - Main" search. &lt;/P&gt;

&lt;P&gt;Below are the steps I've completed so far.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Created a VirusTotal Adaptive Response Action that auto queries the domain of the notable event. This is working very well and I can get the results if I click on my VT notable event.&lt;/LI&gt;
&lt;LI&gt;I created a vtpositives(1) macro that looks like this (I know it's not best practices for some of my search items, this is just a dev system) search index=_* OR index=* VirusTotal "queried url" $query$ source!=audittrail | table positives&lt;/LI&gt;
&lt;LI&gt;When I run the macro from a search and input the URL, it shows the number of positive hits that VirusTotal shows up, which is the field I want to show up in additional fields under the notable event.&lt;/LI&gt;
&lt;LI&gt;I modified the "Incident Review - Main" search to add &lt;CODE&gt;vtpositives(1)&lt;/CODE&gt; right before the &lt;CODE&gt;risk_correlation&lt;/CODE&gt; field that is currently last. I have tried both with the (1) and without it. I know that the "query" field populates correctly within the notable event and the VirusTotal results.&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Once I go to click on the notable events, the page is 100% blank. It does not like my macro at all and prevents any search results from coming up. So my real question is how do I get the positives field out of my search macro and into the notable event?&lt;/P&gt;

&lt;P&gt;For some reason my URLs are not working above so here they are.&lt;BR /&gt;
- &lt;A href="https://answers.splunk.com/answers/481995/splunk-enterprise-security-how-to-add-fields-to-no.html?utm_source=typeahead&amp;amp;utm_medium=newquestion&amp;amp;utm_campaign=no_votes_sort_relev"&gt;https://answers.splunk.com/answers/481995/splunk-enterprise-security-how-to-add-fields-to-no.html?utm_source=typeahead&amp;amp;utm_medium=newquestion&amp;amp;utm_campaign=no_votes_sort_relev&lt;/A&gt;&lt;BR /&gt;
- &lt;A href="http://www.georgestarcher.com/splunk-enterprise-security-enhancing-incident-review/"&gt;http://www.georgestarcher.com/splunk-enterprise-security-enhancing-incident-review/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jan 2019 20:18:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Add-Adaptive-Response-fields-to-Notable-Event/m-p/439174#M5860</guid>
      <dc:creator>ericl42</dc:creator>
      <dc:date>2019-01-31T20:18:27Z</dc:date>
    </item>
  </channel>
</rss>

