<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Clicking on a custom rule's name in ES Top Notable Events doesn't filter in the Incident review in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/688106#M56322</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234826"&gt;@ravida&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;when you created the Correlation Search, did you associate the "Add Notable" Adaptive Response Action?&lt;/P&gt;&lt;P&gt;Then, when you configure the Add Notable Adaptive Response Action, did you created the Drilldown Search?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Tue, 21 May 2024 05:50:44 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2024-05-21T05:50:44Z</dc:date>
    <item>
      <title>Clicking on a custom rule's name in ES Top Notable Events doesn't filter in the Incident review</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/688073#M56318</link>
      <description>&lt;P&gt;Hi folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This has been bugging me for a while. When I click on a custom-made correlation search in the Security Posture's Top Notable Events dashboard pane, it doesn't filter for that rule name in the incident review, it just shows all of them. Where do I configure it to drill down properly?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2024 19:07:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/688073#M56318</guid>
      <dc:creator>ravida</dc:creator>
      <dc:date>2024-05-20T19:07:55Z</dc:date>
    </item>
    <item>
      <title>Re: Clicking on a custom rule's name in ES Top Notable Events doesn't filter in the Incident review</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/688106#M56322</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234826"&gt;@ravida&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;when you created the Correlation Search, did you associate the "Add Notable" Adaptive Response Action?&lt;/P&gt;&lt;P&gt;Then, when you configure the Add Notable Adaptive Response Action, did you created the Drilldown Search?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 05:50:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/688106#M56322</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-05-21T05:50:44Z</dc:date>
    </item>
    <item>
      <title>Re: Clicking on a custom rule's name in ES Top Notable Events doesn't filter in the Incident review</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/688387#M56371</link>
      <description>&lt;P&gt;They are blank. I was under the impression these are for showing the contributing events. Although I am trying to get the "Incident Review" to only show those notables in the list, instead of all notables.&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 20:24:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/688387#M56371</guid>
      <dc:creator>ravida</dc:creator>
      <dc:date>2024-05-22T20:24:21Z</dc:date>
    </item>
    <item>
      <title>Re: Clicking on a custom rule's name in ES Top Notable Events doesn't filter in the Incident review</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/688471#M56380</link>
      <description>&lt;P&gt;&lt;SPAN&gt;They are blank. I was under the impression these are for showing the contributing events. Although I am trying to get the "Incident Review" to only show those notables in the list, instead of all notables.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 13:44:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/688471#M56380</guid>
      <dc:creator>ravida</dc:creator>
      <dc:date>2024-05-23T13:44:27Z</dc:date>
    </item>
    <item>
      <title>Re: Clicking on a custom rule's name in ES Top Notable Events doesn't filter in the Incident review</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/688480#M56381</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234826"&gt;@ravida&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I never experienced this behavior and I'm using many custom Correlation Searches,&lt;/P&gt;&lt;P&gt;Is this issue present for all the CS or only for that?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 14:50:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/688480#M56381</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-05-23T14:50:57Z</dc:date>
    </item>
    <item>
      <title>Re: Clicking on a custom rule's name in ES Top Notable Events doesn't filter in the Incident review</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/688497#M56382</link>
      <description>&lt;P&gt;It happens for all of them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The strange part is, when i first click, you can see the notable name in the URL after "/incident_review?form.rule_name=(rule name)" followed by earliest/latest timestamos&lt;/P&gt;&lt;P&gt;but after a moment it disappears and is replaced with a new URL which only has the earliest/latest values&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 16:53:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/688497#M56382</guid>
      <dc:creator>ravida</dc:creator>
      <dc:date>2024-05-23T16:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: Clicking on a custom rule's name in ES Top Notable Events doesn't filter in the Incident review</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/688557#M56384</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234826"&gt;@ravida&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;as I said,&amp;nbsp;&lt;SPAN&gt;I never experienced this behavior and I'm using many custom Correlation Searches,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Open a case to Splunk Support.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2024 05:48:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/688557#M56384</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-05-24T05:48:04Z</dc:date>
    </item>
    <item>
      <title>Re: Clicking on a custom rule's name in ES Top Notable Events doesn't filter in the Incident review</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/698480#M57261</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;the same story is true for me. Actually after updating ESCU to 4330.&lt;BR /&gt;Not only for custom correlation search rules but for cloned rules.&lt;BR /&gt;before that everything was ok!&lt;BR /&gt;when u clone a built-in rule e.g "Excessive Failed Logins" to something like "Excessive Failed Logins- Custom", in Security Posture's Top Notable Events dashboard pane it appears like "Access - Excessive Failed Logins- Custom - Rule" and when u click on it to open in incident review, it doesn't filter out this as selected source but all incidents are listed as if no filter is selected.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Sep 2024 15:09:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/698480#M57261</guid>
      <dc:creator>Mark_Heimer</dc:creator>
      <dc:date>2024-09-08T15:09:23Z</dc:date>
    </item>
    <item>
      <title>Re: Clicking on a custom rule's name in ES Top Notable Events doesn't filter in the Incident review</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/698517#M57265</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/271988"&gt;@Mark_Heimer&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;did you modified only the Correlation Search name or also the Notable name?&lt;/P&gt;&lt;P&gt;in the Incident Review name you see the Notable name not the Correlations Search name.&lt;/P&gt;&lt;P&gt;In addition, I always prefer, when I clone a CS, move it in a custom app and don't release it in the Enterprise Security apps, in this way, I have all the customizations in a custom app, it isn't mandatory but you have a cleaner and more ordered situation.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2024 06:10:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/698517#M57265</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-09-09T06:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: Clicking on a custom rule's name in ES Top Notable Events doesn't filter in the Incident review</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/698615#M57270</link>
      <description>&lt;P&gt;Hi dear&lt;SPAN class=""&gt; Giuseppe,&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;thanks for fast reply.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;here is what i did.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;I click on Configure menu, then go on to Content/Content Management. From filers I select and check Correlation Search from the drop-down list. then from "Actions" on the top right corner i hit "Clone". &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;in the new window there are "New Search Label" which i add "- custom"&amp;nbsp; to the end of it. then i select the App and put it on "SA-AccessProtection".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;next in "Edit Correlation Search " i&amp;nbsp; will make any change to the "Search" and click save. Done!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;this is all i do.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;The point is even if i enable both of them, the two will appear in the "Top Notable Events" pane and both are working simultaneously. clicking on the original rule redirects u to the "Incident Review" page with the correct rule selected as source. but when clicking on the cloned or newly created rule you'll be redirected to &lt;/SPAN&gt;&lt;SPAN class=""&gt;the "Incident Review" page with all incidents listed and source field has no selected value.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;the strange part is that rules that i had created or cloned in the past (about ) are working fine.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 08:08:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/698615#M57270</guid>
      <dc:creator>Mark_Heimer</dc:creator>
      <dc:date>2024-09-10T08:08:27Z</dc:date>
    </item>
    <item>
      <title>Re: Clicking on a custom rule's name in ES Top Notable Events doesn't filter in the Incident review</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/698624#M57271</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/271988"&gt;@Mark_Heimer&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;you should have, in the bottom of the form, the choice of the Adaptive Response Action, and between them you should have Create Notable.&lt;/P&gt;&lt;P&gt;In this part of the Form, you can modify the name of the Notable.&lt;/P&gt;&lt;P&gt;About the app, Splunk PS hints to save own Correlation Searches in a dedicated custom app not in&amp;nbsp;&lt;SPAN&gt;"SA-AccessProtection".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 09:09:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/698624#M57271</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-09-10T09:09:39Z</dc:date>
    </item>
    <item>
      <title>Re: Clicking on a custom rule's name in ES Top Notable Events doesn't filter in the Incident review</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/698628#M57272</link>
      <description>&lt;P&gt;Hi&amp;nbsp; dear Giuseppe,&lt;/P&gt;&lt;P&gt;when i clone a rule, Adaptive Response Actions&amp;nbsp; options (i.e. Notable) and most of the times, Risk Analysis are present by default as are other fields and options the same as the original rule. that's why i clone a rule.&lt;/P&gt;&lt;P&gt;second, i used to do so for a long time but never had come up with this problem. and as you mentioned earlier my custom rules were working just fine.&lt;/P&gt;&lt;P&gt;about the app, i used my custom app and "SA-AccessProtection" was my last try.&lt;/P&gt;&lt;P&gt;And for newly created custom app i do create notable.&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 09:55:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/698628#M57272</guid>
      <dc:creator>Mark_Heimer</dc:creator>
      <dc:date>2024-09-10T09:55:12Z</dc:date>
    </item>
    <item>
      <title>Re: Clicking on a custom rule's name in ES Top Notable Events doesn't filter in the Incident review</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/698632#M57273</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/271988"&gt;@Mark_Heimer&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;obviously cloning a CS you have the same settings of the original one, so also the same Notable name.&lt;/P&gt;&lt;P&gt;My hint is to enter in the cloned Create Notable Adaptive Response Action, and modify the Notable Name, in this way, you'll have in the Incident View the modified name.&lt;/P&gt;&lt;P&gt;About the app to contain the custom CSs, this is an hint from PS.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 11:00:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/698632#M57273</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-09-10T11:00:49Z</dc:date>
    </item>
    <item>
      <title>Re: Clicking on a custom rule's name in ES Top Notable Events doesn't filter in the Incident review</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/698650#M57274</link>
      <description>&lt;P&gt;Hi Giuseppe,&lt;/P&gt;&lt;P&gt;I did exactly what you said. but no luck!&lt;/P&gt;&lt;P&gt;In another try, I even created a search and saved it as an alert, named it "rule-4444" then added a notable to it as an action.&lt;/P&gt;&lt;P&gt;it appeared as "rule-4444" in the "Top Notable Events" in the Security Posture page. but when i click on it, it is redirected to incident review page but again all incidents listed.&lt;/P&gt;&lt;P&gt;the same thing as ravida says happening.&lt;/P&gt;&lt;P&gt;when u first click on it, you can see the notable name in the URL after (incident review page )"/incident_review?form.rule_name=rule-4444" followed by earliest/latest timestamps&lt;/P&gt;&lt;P&gt;but after a while when the page load completes it disappears and is replaced with a new URL which only has the earliest/latest values&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 13:22:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/698650#M57274</guid>
      <dc:creator>Mark_Heimer</dc:creator>
      <dc:date>2024-09-10T13:22:57Z</dc:date>
    </item>
    <item>
      <title>Re: Clicking on a custom rule's name in ES Top Notable Events doesn't filter in the Incident review</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/698750#M57280</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Another strange thing that happens to me and i just realized is that when i refresh the page "incident Review" with correctly loaded filters and showing true notable results, the filter "source" becomes something like this:&lt;/P&gt;&lt;P&gt;source: Access%20-%20Excessive%20Failed%20Logins%20-%20Rule&lt;/P&gt;&lt;P&gt;And no results are shown on the page after page refresh.&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 09:14:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/698750#M57280</guid>
      <dc:creator>Mark_Heimer</dc:creator>
      <dc:date>2024-09-11T09:14:07Z</dc:date>
    </item>
    <item>
      <title>Re: Clicking on a custom rule's name in ES Top Notable Events doesn't filter in the Incident review</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/698755#M57281</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/271988"&gt;@Mark_Heimer&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;check how you created the drilldown filter, because these are html codes.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 09:41:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Clicking-on-a-custom-rule-s-name-in-ES-Top-Notable-Events-doesn/m-p/698755#M57281</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-09-11T09:41:20Z</dc:date>
    </item>
  </channel>
</rss>

