- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
H classification is Threat, even though I chose endpoin
Hello everyone, I do not know why the classification is Threat, even though I chose endpoin
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @tuts ,
go in the ES menu item [Settings > Configure > Contents]
choose the related Correlation Search and see in the Notable Section what's the configured Security Domain.
probably the Threat Security Domain is associated to your Correlation Search and it's bundled in the CS name.
In this case you have to clone the CS, using the correct Security Domain and delete the old one.
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I did the same steps and still have the same problem
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is the search, but whatever you choose from a domain, it categorizes it as a threat
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @tuts ,
as I said, the Threat Security Domain is in the name of the Correlation Search.
Clone your CS and change the Security Domain.
You'll have a new CS with the correct name.
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you mean that, I did it and still have the same problem.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I am new in this field, is it possible to explain the solution step by step?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @tuts ,
please try this:
- from the list of the Correlation Searches, clone your one (link on the right side),
- edit the new Correlation Search using the correct Security Domain,
- Save it.
- disable and then delete the old Correlatin Search.
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I did the same steps and still have the same problem
I did the same steps and still have the same problem
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
here
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I really don't know what to do, all I want is to adopt the security domains that I want
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Welcome to you engineer I did not understand where to go can you explain to me more I am new to splunk and about two months I am looking for a solution to the problem
