Security

How to correlate two rules/alert into a third

matheusvortex
Loves-to-Learn

Hello everyone,

How can I correlate two alerts into a third one?

For instance:
I have alert 1 and alert 2 both with medium severity.
I need the following validation in alert 3:
If, after 6 hours since alert 1 was triggered, alert 2 is triggered as well, generate alert 3 with high severity.

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Alerts are based on results of a search - for an alert to be triggered based on two conditions, your search needs to find both conditions.

0 Karma

matheusvortex
Loves-to-Learn

I understand. You can make a little progress using the strategy of pulling alerts that are triggered. My research is as follows:

index=_audit action="alert_fired" ss_app=search ss_name="alert 1" OR ss_name="alert 2"
| rename ss_name AS title
| stats count by title, ss_app, _time
| sort -_time

In this research I can bring up the two alerts that I want to combine. Is it possible to get certain fields from these two alerts?

In this case, I want to get the user. I can only generate the alert if the user is the same, the problem is that there are two different log providers and therefore, the field that has the user value has different names.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @matheusvortex ,

you could write the results of the two searches in one summary index (called e.g. Notables), adding in each alert all the fields you need and then execute the third alert on the summary index displaying the fields you need.

Ciao.

Giuseppe

This is the approach of Enterprise Security.

0 Karma

matheusvortex
Loves-to-Learn

Could you support me, what would this research look like?

0 Karma

matheusvortex
Loves-to-Learn

I understand. I managed to make a little progress using the strategy of pulling through triggered alerts. My research is as follows:******

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...