All Apps and Add-ons

Unable to set the "action.threat_activity" to "1" from the advanced edit option of the saved search

renjujacob88
Path Finder

Hi Splunkers,

I just created a saved search and my agenda is to write the event to threat_activity index.

To do this i need to enable "action.threat_activity" param to 1. But when i change the parameter to 1 and save it its not updating instead its showing as action.threat_activity=0.

Is there a work around on this issue. The only thing i need is to write the saved search result to threat_activity.

Kindly help

alt text

0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...