Security

Notable Response Actions -- Is there a way to override the standard Trigger Condition rule?

weimsec
New Member

Hello!

I am looking for a way to override the built-in Trigger Condition for Notable Response Actions, "For each result".

I'd like Notable Response Actions to only be triggered "Once" so results/events are more consolidated to work with my other tools more efficiently.

See the screenshot image. It notes that "Notable response actions and risk response actions are always triggered for each result" despite the Trigger being set to "Once":

Is there anyway to override this for Notable Response Actions to be triggered once as configured?

Thanks for your help!

(This setting is found under the Configure -> Content -> Content Management settings after selecting a specific security alert to edit).

weimsec_0-1656525242221.png

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...