<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: mitre visualisation for notable in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/mitre-visualisation-for-notable/m-p/690337#M56563</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/268899"&gt;@user487596&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;yes, in Security Essentials App you have also a MITRE visualization, but I'm hinting to use the above MITRE ATT&amp;amp;CK app.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Tue, 11 Jun 2024 13:39:33 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2024-06-11T13:39:33Z</dc:date>
    <item>
      <title>mitre visualisation for notable</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/mitre-visualisation-for-notable/m-p/690319#M56555</link>
      <description>&lt;P&gt;Hello everyone, I'm new to Splunk, can anyone help me: enable "Using visualizations to determine TTP coverage" from&amp;nbsp;&lt;A href="https://lantern.splunk.com/?title=Security%2FUCE%2FGuided_Insights%2FCyber_frameworks%2FAssessing_and_expanding_MITRE_ATT%26CK_coverage_in_Splunk_Enterprise_Security#" target="_blank" rel="noopener"&gt;https://lantern.splunk.com/?title=Security%2FUCE%2FGuided_Insights%2FCyber_frameworks%2FAssessing_and_expanding_MITRE_ATT%26CK_coverage_in_Splunk_Enterprise_Security#&lt;/A&gt;&amp;nbsp;?&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/ES/7.1.0/RBA/ViewMitreMatrixforRiskNotable#View_the_MITRE_ATT.26CK_posture_for_a_risk_notable," target="_blank" rel="nofollow noopener noreferrer"&gt;https://docs.splunk.com/Documentation/ES/7.1.0/RBA/ViewMitreMatrixforRiskNotable#View_the_MITRE_ATT....&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;LI-PRODUCT title="Splunk Enterprise Security" id="263"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Splunk Security Essentials" id="3435"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 16:52:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/mitre-visualisation-for-notable/m-p/690319#M56555</guid>
      <dc:creator>user487596</dc:creator>
      <dc:date>2024-06-11T16:52:38Z</dc:date>
    </item>
    <item>
      <title>Re: mitre visualisation for notable</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/mitre-visualisation-for-notable/m-p/690328#M56559</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/268899"&gt;@user487596&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;to help you, I need some additional information:&lt;/P&gt;&lt;P&gt;what's your issue?&lt;/P&gt;&lt;P&gt;did you installed the Splunk MITRE ATT&amp;amp;CK app (&lt;A href="https://splunkbase.splunk.com/app/4617" target="_blank"&gt;https://splunkbase.splunk.com/app/4617&lt;/A&gt;&amp;nbsp;)?&lt;/P&gt;&lt;P&gt;are you working inside Enterprise Security or not?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 13:24:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/mitre-visualisation-for-notable/m-p/690328#M56559</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-06-11T13:24:29Z</dc:date>
    </item>
    <item>
      <title>Re: mitre visualisation for notable</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/mitre-visualisation-for-notable/m-p/690330#M56560</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;don't see "MITRE ATTACK App for Splunk" in apps; yes, i'am &lt;SPAN&gt;work inside Enterprise Security&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 13:29:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/mitre-visualisation-for-notable/m-p/690330#M56560</guid>
      <dc:creator>user487596</dc:creator>
      <dc:date>2024-06-11T13:29:26Z</dc:date>
    </item>
    <item>
      <title>Re: mitre visualisation for notable</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/mitre-visualisation-for-notable/m-p/690333#M56561</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/268899"&gt;@user487596&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;install it from Splunkbase I always use it: you'll find inside it useful Use Cases for ES.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 13:32:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/mitre-visualisation-for-notable/m-p/690333#M56561</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-06-11T13:32:15Z</dc:date>
    </item>
    <item>
      <title>Re: mitre visualisation for notable</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/mitre-visualisation-for-notable/m-p/690334#M56562</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;, what about MITRE ATT&amp;amp;CK Framework in&amp;nbsp;Splunk Security Essentials,&amp;nbsp;which, as I understand it, is already built in, Is it impossible to work with it or is it easier with your application?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 13:36:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/mitre-visualisation-for-notable/m-p/690334#M56562</guid>
      <dc:creator>user487596</dc:creator>
      <dc:date>2024-06-11T13:36:17Z</dc:date>
    </item>
    <item>
      <title>Re: mitre visualisation for notable</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/mitre-visualisation-for-notable/m-p/690337#M56563</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/268899"&gt;@user487596&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;yes, in Security Essentials App you have also a MITRE visualization, but I'm hinting to use the above MITRE ATT&amp;amp;CK app.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 13:39:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/mitre-visualisation-for-notable/m-p/690337#M56563</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-06-11T13:39:33Z</dc:date>
    </item>
    <item>
      <title>Re: mitre visualisation for notable</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/mitre-visualisation-for-notable/m-p/690338#M56564</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&amp;nbsp;The application is cool, but I would like to understand the built-in capabilities. Is there any documentation or tips on how to set up visualization without third-party applications?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 13:41:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/mitre-visualisation-for-notable/m-p/690338#M56564</guid>
      <dc:creator>user487596</dc:creator>
      <dc:date>2024-06-11T13:41:47Z</dc:date>
    </item>
    <item>
      <title>Re: mitre visualisation for notable</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/mitre-visualisation-for-notable/m-p/690341#M56565</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/268899"&gt;@user487596&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;as I said, I always use the MITRE ATT&amp;amp;CK app, but if you want to use only the Security Essentials, see this:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/SSE/3.8.0/User/MITREFramework" target="_blank"&gt;https://docs.splunk.com/Documentation/SSE/3.8.0/User/MITREFramework&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 13:55:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/mitre-visualisation-for-notable/m-p/690341#M56565</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-06-11T13:55:05Z</dc:date>
    </item>
    <item>
      <title>Re: mitre visualisation for notable</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/mitre-visualisation-for-notable/m-p/690348#M56566</link>
      <description>&lt;P&gt;doesn't look like what i need, it's just a dashboard&amp;nbsp;&lt;BR /&gt;i need this&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/ES/7.1.0/RBA/ViewMitreMatrixforRiskNotable#View_the_MITRE_ATT.26CK_posture_for_a_risk_notable," target="_blank"&gt;https://docs.splunk.com/Documentation/ES/7.1.0/RBA/ViewMitreMatrixforRiskNotable#View_the_MITRE_ATT.26CK_posture_for_a_risk_notable&lt;/A&gt;&amp;nbsp;the problem is that the event doesn't have this (MITRE ATT&amp;amp;CK Posture for this Notable) information in notable... how to add it?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 14:44:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/mitre-visualisation-for-notable/m-p/690348#M56566</guid>
      <dc:creator>user487596</dc:creator>
      <dc:date>2024-06-11T14:44:05Z</dc:date>
    </item>
    <item>
      <title>Re: mitre visualisation for notable</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/mitre-visualisation-for-notable/m-p/690970#M56608</link>
      <description>&lt;P&gt;The answer in &lt;A href="https://www.splunk.com/en_us/blog/security/do-more-with-splunk-security-essentials-3-7-0.html" target="_self"&gt;this splunk blog post.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Somewhere in "System Configuration" we can configure integration with ES. Nuance - I opened this settings menu once, but the second time I can’t find it &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2024 08:32:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/mitre-visualisation-for-notable/m-p/690970#M56608</guid>
      <dc:creator>user487596</dc:creator>
      <dc:date>2024-06-18T08:32:01Z</dc:date>
    </item>
  </channel>
</rss>

