Splunk Enterprise Security

Add custom tag on close of ES Incident

willadams
Contributor

We have a number of correlation searches that trigger in Enterprise Security. From these events that trigger in IR, some events are true positive others are not. What I am trying to do is have my analysts mark the notable event with something like a tag to indicate whether the alert was a true positive or not. At the moment, the only way I have been able to do this is have the analyst type this in the closing comments of an event. This would work perfectly fine, except that this requires an analyst to (1) remember, (2) put it in the right format (i.e. someone may type is false positive or fp or false-positive etc.) and (3) put it in the same spot.

Is there a way in Incident Review (via the incident_review index) to populate additional information when an event is closed with a tag about the event. I am not sure if this can be added as an action (as opposed to an adaptive invocation action). While Security Posture provides me a count of a particular notable event, I would like to extend this beyond just the count (i.e. notable event number but how many were false positives, how many were true positives, etc...)

0 Karma
1 Solution

willadams
Contributor

I thought about this some more and the simplest thing to do is probably just create a new status with the codes I want.

View solution in original post

0 Karma

willadams
Contributor

I thought about this some more and the simplest thing to do is probably just create a new status with the codes I want.

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...