<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to ignore unknown objects in Risk adaptive response? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-ignore-unknown-objects-in-Risk-adaptive-response/m-p/554809#M9965</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/177803"&gt;@lakshman239&lt;/a&gt;&amp;nbsp;There's is no "unknown" source from my intelligence. Indeed, some of my incidents got a IP hit my intelligence. So the score of the exact IP keeps raising which is reasonable. However, the same incident also has "unknown" src or user, make "unknown" got high score as well.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 08 Jun 2021 02:55:24 GMT</pubDate>
    <dc:creator>phil_wong</dc:creator>
    <dc:date>2021-06-08T02:55:24Z</dc:date>
    <item>
      <title>How to ignore unknown objects in Risk adaptive response?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-ignore-unknown-objects-in-Risk-adaptive-response/m-p/554585#M9954</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;There're some incidents hit my threat intelligence IP, e.g. dest. That's why Threat Activity notable event is triggered which is good to see.&lt;/P&gt;&lt;P&gt;However, my concern is it would at the same time multiple the score of "unknown" user and "unknown" src/dest.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;How can I filter these noise effectively, so not so many false alert introduced by "unknown" user or IP?&lt;/P&gt;</description>
      <pubDate>Sat, 05 Jun 2021 08:56:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-ignore-unknown-objects-in-Risk-adaptive-response/m-p/554585#M9954</guid>
      <dc:creator>phil_wong</dc:creator>
      <dc:date>2021-06-05T08:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to ignore unknown objects in Risk adaptive response?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-ignore-unknown-objects-in-Risk-adaptive-response/m-p/554653#M9957</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228013"&gt;@phil_wong&lt;/a&gt;&amp;nbsp; You would probably want to check the source- threat list activity for the duration that had unknown and find out which event is causing this? its most likely sending 'null' and causing this. If you can fix that, that could avoid 'unknown's coming in the rule/correlation searches.&lt;/P&gt;&lt;P&gt;hope this helps.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jun 2021 10:08:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-ignore-unknown-objects-in-Risk-adaptive-response/m-p/554653#M9957</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2021-06-07T10:08:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to ignore unknown objects in Risk adaptive response?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-ignore-unknown-objects-in-Risk-adaptive-response/m-p/554809#M9965</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/177803"&gt;@lakshman239&lt;/a&gt;&amp;nbsp;There's is no "unknown" source from my intelligence. Indeed, some of my incidents got a IP hit my intelligence. So the score of the exact IP keeps raising which is reasonable. However, the same incident also has "unknown" src or user, make "unknown" got high score as well.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 02:55:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-ignore-unknown-objects-in-Risk-adaptive-response/m-p/554809#M9965</guid>
      <dc:creator>phil_wong</dc:creator>
      <dc:date>2021-06-08T02:55:24Z</dc:date>
    </item>
  </channel>
</rss>

