Security

Notable Response Actions -- Is there a way to override the standard Trigger Condition rule?

weimsec
New Member

Hello!

I am looking for a way to override the built-in Trigger Condition for Notable Response Actions, "For each result".

I'd like Notable Response Actions to only be triggered "Once" so results/events are more consolidated to work with my other tools more efficiently.

See the screenshot image. It notes that "Notable response actions and risk response actions are always triggered for each result" despite the Trigger being set to "Once":

Is there anyway to override this for Notable Response Actions to be triggered once as configured?

Thanks for your help!

(This setting is found under the Configure -> Content -> Content Management settings after selecting a specific security alert to edit).

weimsec_0-1656525242221.png

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...