Hello everyone, I do not know why the classification is Threat, even though I chose endpoin
Hi @tuts ,
go in the ES menu item [Settings > Configure > Contents]
choose the related Correlation Search and see in the Notable Section what's the configured Security Domain.
probably the Threat Security Domain is associated to your Correlation Search and it's bundled in the CS name.
In this case you have to clone the CS, using the correct Security Domain and delete the old one.
Ciao.
Giuseppe
I did the same steps and still have the same problem
This is the search, but whatever you choose from a domain, it categorizes it as a threat
Hi @tuts ,
as I said, the Threat Security Domain is in the name of the Correlation Search.
Clone your CS and change the Security Domain.
You'll have a new CS with the correct name.
Ciao.
Giuseppe
If you mean that, I did it and still have the same problem.
I am new in this field, is it possible to explain the solution step by step?
Hi @tuts ,
please try this:
Ciao.
Giuseppe
I did the same steps and still have the same problem
I did the same steps and still have the same problem
here
I really don't know what to do, all I want is to adopt the security domains that I want
Welcome to you engineer I did not understand where to go can you explain to me more I am new to splunk and about two months I am looking for a solution to the problem