Security

Notable Response Actions -- Is there a way to override the standard Trigger Condition rule?

weimsec
New Member

Hello!

I am looking for a way to override the built-in Trigger Condition for Notable Response Actions, "For each result".

I'd like Notable Response Actions to only be triggered "Once" so results/events are more consolidated to work with my other tools more efficiently.

See the screenshot image. It notes that "Notable response actions and risk response actions are always triggered for each result" despite the Trigger being set to "Once":

Is there anyway to override this for Notable Response Actions to be triggered once as configured?

Thanks for your help!

(This setting is found under the Configure -> Content -> Content Management settings after selecting a specific security alert to edit).

weimsec_0-1656525242221.png

 

0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...