<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Null value for urgency in incident_review lookup in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Null-value-for-urgency-in-incident-review-lookup/m-p/454262#M6383</link>
    <description>&lt;P&gt;Hi Splunkers,&lt;/P&gt;

&lt;P&gt;when we save\close notable events without changing the Urgency we get no any value (null) for &lt;CODE&gt;urgency&lt;/CODE&gt; in &lt;CODE&gt;incident_review_lookup&lt;/CODE&gt;. &lt;BR /&gt;
In ES &lt;CODE&gt;Incident Review&lt;/CODE&gt; view the Urgency is shown and just has initial value (as expected). &lt;BR /&gt;
Is it possible to get the default value for urgency in lookup in case we want to  leave urgency as is?&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7277i43BD67732ADDFD9D/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;  &lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7278i8C92BDCF866F4A16/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 02 Jul 2019 16:36:43 GMT</pubDate>
    <dc:creator>evelenke</dc:creator>
    <dc:date>2019-07-02T16:36:43Z</dc:date>
    <item>
      <title>Null value for urgency in incident_review lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Null-value-for-urgency-in-incident-review-lookup/m-p/454262#M6383</link>
      <description>&lt;P&gt;Hi Splunkers,&lt;/P&gt;

&lt;P&gt;when we save\close notable events without changing the Urgency we get no any value (null) for &lt;CODE&gt;urgency&lt;/CODE&gt; in &lt;CODE&gt;incident_review_lookup&lt;/CODE&gt;. &lt;BR /&gt;
In ES &lt;CODE&gt;Incident Review&lt;/CODE&gt; view the Urgency is shown and just has initial value (as expected). &lt;BR /&gt;
Is it possible to get the default value for urgency in lookup in case we want to  leave urgency as is?&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7277i43BD67732ADDFD9D/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;  &lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7278i8C92BDCF866F4A16/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 16:36:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Null-value-for-urgency-in-incident-review-lookup/m-p/454262#M6383</guid>
      <dc:creator>evelenke</dc:creator>
      <dc:date>2019-07-02T16:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: Null value for urgency in incident_review lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Null-value-for-urgency-in-incident-review-lookup/m-p/454263#M6384</link>
      <description>&lt;P&gt;One of my customers had this situation before and it turned out that the severity was being assigned an unknown value in the correlation search. Take a look at the ES documentation for determining urgency. &lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/ES/5.3.1/User/Howurgencyisassigned"&gt;https://docs.splunk.com/Documentation/ES/5.3.1/User/Howurgencyisassigned&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;In the customer's case, the assigned priority was being overwritten in the correlation search. It was being set to a value that was not in the blue or gold sections of the urgency table (see link). &lt;/P&gt;

&lt;P&gt;So for example ES expects the Assigned Priority to be &lt;EM&gt;Unknown, Low, Medium, High, or Critical&lt;/EM&gt;. If your correlation search mistakenly sets a field called priority to &lt;STRONG&gt;Informational&lt;/STRONG&gt; then ES cannot correctly calculate the urgency. You will get a NULL value.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2019 15:43:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Null-value-for-urgency-in-incident-review-lookup/m-p/454263#M6384</guid>
      <dc:creator>nswondem</dc:creator>
      <dc:date>2019-09-24T15:43:21Z</dc:date>
    </item>
  </channel>
</rss>

