<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic cvss score result not available in Splunk Enterprise Security module in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/cvss-score-result-not-available-in-Splunk-Enterprise-Security/m-p/449987#M6230</link>
    <description>&lt;P&gt;Hi Experts,&lt;/P&gt;

&lt;P&gt;I am trying to setup a glasstable containing the result from cvss score field. &lt;/P&gt;

&lt;P&gt;I seem to get other result related to this (CVE, crticality level etc.) but the cvss field is not extracted. I can see that the field is available in the "vulnerability" datamodel.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 06 Sep 2018 08:38:59 GMT</pubDate>
    <dc:creator>tfrandsen</dc:creator>
    <dc:date>2018-09-06T08:38:59Z</dc:date>
    <item>
      <title>cvss score result not available in Splunk Enterprise Security module</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/cvss-score-result-not-available-in-Splunk-Enterprise-Security/m-p/449987#M6230</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;

&lt;P&gt;I am trying to setup a glasstable containing the result from cvss score field. &lt;/P&gt;

&lt;P&gt;I seem to get other result related to this (CVE, crticality level etc.) but the cvss field is not extracted. I can see that the field is available in the "vulnerability" datamodel.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 08:38:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/cvss-score-result-not-available-in-Splunk-Enterprise-Security/m-p/449987#M6230</guid>
      <dc:creator>tfrandsen</dc:creator>
      <dc:date>2018-09-06T08:38:59Z</dc:date>
    </item>
    <item>
      <title>Re: cvss score result not available in Splunk Enterprise Security module</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/cvss-score-result-not-available-in-Splunk-Enterprise-Security/m-p/449988#M6231</link>
      <description>&lt;P&gt;Is the CVSS score field present in your events?  The datamodel can't extract what's not in the data.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 11:59:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/cvss-score-result-not-available-in-Splunk-Enterprise-Security/m-p/449988#M6231</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2018-09-06T11:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: cvss score result not available in Splunk Enterprise Security module</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/cvss-score-result-not-available-in-Splunk-Enterprise-Security/m-p/449989#M6232</link>
      <description>&lt;P&gt;With events do you mean incident review panel? the cvss score is not showed in either the incident review panel or in search results. &lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 12:05:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/cvss-score-result-not-available-in-Splunk-Enterprise-Security/m-p/449989#M6232</guid>
      <dc:creator>tfrandsen</dc:creator>
      <dc:date>2018-09-06T12:05:42Z</dc:date>
    </item>
    <item>
      <title>Re: cvss score result not available in Splunk Enterprise Security module</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/cvss-score-result-not-available-in-Splunk-Enterprise-Security/m-p/449990#M6233</link>
      <description>&lt;P&gt;The field is not present in the search result &lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 12:06:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/cvss-score-result-not-available-in-Splunk-Enterprise-Security/m-p/449990#M6233</guid>
      <dc:creator>tfrandsen</dc:creator>
      <dc:date>2018-09-06T12:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: cvss score result not available in Splunk Enterprise Security module</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/cvss-score-result-not-available-in-Splunk-Enterprise-Security/m-p/449991#M6234</link>
      <description>&lt;P&gt;I can see the cvss score result in my splunk module where i have Qualys app installed. Its just in my SIEM i cant see it&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 12:07:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/cvss-score-result-not-available-in-Splunk-Enterprise-Security/m-p/449991#M6234</guid>
      <dc:creator>tfrandsen</dc:creator>
      <dc:date>2018-09-06T12:07:33Z</dc:date>
    </item>
    <item>
      <title>Re: cvss score result not available in Splunk Enterprise Security module</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/cvss-score-result-not-available-in-Splunk-Enterprise-Security/m-p/449992#M6235</link>
      <description>&lt;P&gt;So the CVSS score field is present , but is not being extracted by the data model.  You'll need to edit the data model to extract the field from your events.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 18:35:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/cvss-score-result-not-available-in-Splunk-Enterprise-Security/m-p/449992#M6235</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2018-09-06T18:35:12Z</dc:date>
    </item>
    <item>
      <title>Re: cvss score result not available in Splunk Enterprise Security module</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/cvss-score-result-not-available-in-Splunk-Enterprise-Security/m-p/449993#M6236</link>
      <description>&lt;P&gt;How and what do I edit in the data model to extract the data. Have not been able to find information about this online&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 19:06:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/cvss-score-result-not-available-in-Splunk-Enterprise-Security/m-p/449993#M6236</guid>
      <dc:creator>tfrandsen</dc:creator>
      <dc:date>2018-09-06T19:06:30Z</dc:date>
    </item>
  </channel>
</rss>

