Security

Notable Response Actions -- Is there a way to override the standard Trigger Condition rule?

weimsec
New Member

Hello!

I am looking for a way to override the built-in Trigger Condition for Notable Response Actions, "For each result".

I'd like Notable Response Actions to only be triggered "Once" so results/events are more consolidated to work with my other tools more efficiently.

See the screenshot image. It notes that "Notable response actions and risk response actions are always triggered for each result" despite the Trigger being set to "Once":

Is there anyway to override this for Notable Response Actions to be triggered once as configured?

Thanks for your help!

(This setting is found under the Configure -> Content -> Content Management settings after selecting a specific security alert to edit).

weimsec_0-1656525242221.png

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...