Security

Notable Response Actions -- Is there a way to override the standard Trigger Condition rule?

weimsec
New Member

Hello!

I am looking for a way to override the built-in Trigger Condition for Notable Response Actions, "For each result".

I'd like Notable Response Actions to only be triggered "Once" so results/events are more consolidated to work with my other tools more efficiently.

See the screenshot image. It notes that "Notable response actions and risk response actions are always triggered for each result" despite the Trigger being set to "Once":

Is there anyway to override this for Notable Response Actions to be triggered once as configured?

Thanks for your help!

(This setting is found under the Configure -> Content -> Content Management settings after selecting a specific security alert to edit).

weimsec_0-1656525242221.png

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...