Splunk Enterprise Security

Add custom tag on close of ES Incident

willadams
Contributor

We have a number of correlation searches that trigger in Enterprise Security. From these events that trigger in IR, some events are true positive others are not. What I am trying to do is have my analysts mark the notable event with something like a tag to indicate whether the alert was a true positive or not. At the moment, the only way I have been able to do this is have the analyst type this in the closing comments of an event. This would work perfectly fine, except that this requires an analyst to (1) remember, (2) put it in the right format (i.e. someone may type is false positive or fp or false-positive etc.) and (3) put it in the same spot.

Is there a way in Incident Review (via the incident_review index) to populate additional information when an event is closed with a tag about the event. I am not sure if this can be added as an action (as opposed to an adaptive invocation action). While Security Posture provides me a count of a particular notable event, I would like to extend this beyond just the count (i.e. notable event number but how many were false positives, how many were true positives, etc...)

0 Karma
1 Solution

willadams
Contributor

I thought about this some more and the simplest thing to do is probably just create a new status with the codes I want.

View solution in original post

0 Karma

willadams
Contributor

I thought about this some more and the simplest thing to do is probably just create a new status with the codes I want.

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...