All Apps and Add-ons

Unable to set the "action.threat_activity" to "1" from the advanced edit option of the saved search

Path Finder

Hi Splunkers,

I just created a saved search and my agenda is to write the event to threat_activity index.

To do this i need to enable "action.threat_activity" param to 1. But when i change the parameter to 1 and save it its not updating instead its showing as action.threat_activity=0.

Is there a work around on this issue. The only thing i need is to write the saved search result to threat_activity.

Kindly help

alt text

0 Karma
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!