<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Once vs For Each Notable Response Actions Clarification in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Once-vs-For-Each-Notable-Response-Actions-Clarification/m-p/693200#M16128</link>
    <description>&lt;P&gt;Yeah maybe some others will chime in. The only thing I can think of is that the number of alerts that show up in Triggered Alerts would be different depending on which option ("Once" or "For each") you select. I saw this &lt;A title="Notable Response Actions -- Is there a way to override the standard Trigger Condition rule?" href="https://community.splunk.com/t5/Security/Notable-Response-Actions-Is-there-a-way-to-override-the-standard/m-p/603842" target="_blank" rel="noopener"&gt;post&lt;/A&gt; which is sort of similar, but no one responded to it.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jul 2024 17:34:22 GMT</pubDate>
    <dc:creator>mobrien1</dc:creator>
    <dc:date>2024-07-12T17:34:22Z</dc:date>
    <item>
      <title>Once vs For Each Notable Response Actions Clarification</title>
      <link>https://community.splunk.com/t5/Alerting/Once-vs-For-Each-Notable-Response-Actions-Clarification/m-p/693108#M16122</link>
      <description>&lt;P&gt;I wanted to get some clarification on how trigger conditions effect n&lt;SPAN&gt;otable response actions for correlation searches in Enterprise Security. The trigger condition options are between "Once" and "For each Result", and I believe I understand the difference. However, under them there is a little blurb that says "Notable response actions and risk response actions are always triggered for each result."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mobrien1_0-1720722111909.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31714i1F4259F89AEB215A/image-size/large?v=v2&amp;amp;px=999" role="button" title="mobrien1_0-1720722111909.png" alt="mobrien1_0-1720722111909.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;To me, this essentially nullifies "Once" since the action will be triggered for each result. As a result, I fail to see how "Once" is any different than&amp;nbsp;&lt;SPAN&gt;"For each Result". But surely they can't be the same.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 18:31:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Once-vs-For-Each-Notable-Response-Actions-Clarification/m-p/693108#M16122</guid>
      <dc:creator>mobrien1</dc:creator>
      <dc:date>2024-07-11T18:31:06Z</dc:date>
    </item>
    <item>
      <title>Re: Once vs For Each Notable Response Actions Clarification</title>
      <link>https://community.splunk.com/t5/Alerting/Once-vs-For-Each-Notable-Response-Actions-Clarification/m-p/693147#M16125</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/266258"&gt;@mobrien1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I suppose that the meanng of the affermation is that e.g. risk score is counted for each value you can find in the results of your Correlation Search, so if you have more hosts in the results, the Risk Score is counted for all of them.&lt;/P&gt;&lt;P&gt;But, why did you posted this question?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2024 07:06:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Once-vs-For-Each-Notable-Response-Actions-Clarification/m-p/693147#M16125</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-07-12T07:06:05Z</dc:date>
    </item>
    <item>
      <title>Re: Once vs For Each Notable Response Actions Clarification</title>
      <link>https://community.splunk.com/t5/Alerting/Once-vs-For-Each-Notable-Response-Actions-Clarification/m-p/693193#M16126</link>
      <description>&lt;P&gt;I think I would agree with your first statement.&lt;/P&gt;&lt;P&gt;But the reason I posted this question is that the phrase "&lt;SPAN&gt;Notable response actions and risk response actions are always triggered for each result." effectively makes "Once" and "For each result" the same thing (at least in my mind). But they are two distinct options, so I feel like they can't be the same. This makes me think I'm misunderstanding something.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2024 13:59:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Once-vs-For-Each-Notable-Response-Actions-Clarification/m-p/693193#M16126</guid>
      <dc:creator>mobrien1</dc:creator>
      <dc:date>2024-07-12T13:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: Once vs For Each Notable Response Actions Clarification</title>
      <link>https://community.splunk.com/t5/Alerting/Once-vs-For-Each-Notable-Response-Actions-Clarification/m-p/693195#M16127</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/266258"&gt;@mobrien1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;maybe&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;"Once" and "For each result" became from Alerts.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I don't find any other answer.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;let me know if I can help you more, or, please, accept one answer for the other people of Community.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2024 14:04:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Once-vs-For-Each-Notable-Response-Actions-Clarification/m-p/693195#M16127</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-07-12T14:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: Once vs For Each Notable Response Actions Clarification</title>
      <link>https://community.splunk.com/t5/Alerting/Once-vs-For-Each-Notable-Response-Actions-Clarification/m-p/693200#M16128</link>
      <description>&lt;P&gt;Yeah maybe some others will chime in. The only thing I can think of is that the number of alerts that show up in Triggered Alerts would be different depending on which option ("Once" or "For each") you select. I saw this &lt;A title="Notable Response Actions -- Is there a way to override the standard Trigger Condition rule?" href="https://community.splunk.com/t5/Security/Notable-Response-Actions-Is-there-a-way-to-override-the-standard/m-p/603842" target="_blank" rel="noopener"&gt;post&lt;/A&gt; which is sort of similar, but no one responded to it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2024 17:34:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Once-vs-For-Each-Notable-Response-Actions-Clarification/m-p/693200#M16128</guid>
      <dc:creator>mobrien1</dc:creator>
      <dc:date>2024-07-12T17:34:22Z</dc:date>
    </item>
  </channel>
</rss>

