Splunk Enterprise Security

Add custom tag on close of ES Incident

willadams
Contributor

We have a number of correlation searches that trigger in Enterprise Security. From these events that trigger in IR, some events are true positive others are not. What I am trying to do is have my analysts mark the notable event with something like a tag to indicate whether the alert was a true positive or not. At the moment, the only way I have been able to do this is have the analyst type this in the closing comments of an event. This would work perfectly fine, except that this requires an analyst to (1) remember, (2) put it in the right format (i.e. someone may type is false positive or fp or false-positive etc.) and (3) put it in the same spot.

Is there a way in Incident Review (via the incident_review index) to populate additional information when an event is closed with a tag about the event. I am not sure if this can be added as an action (as opposed to an adaptive invocation action). While Security Posture provides me a count of a particular notable event, I would like to extend this beyond just the count (i.e. notable event number but how many were false positives, how many were true positives, etc...)

0 Karma
1 Solution

willadams
Contributor

I thought about this some more and the simplest thing to do is probably just create a new status with the codes I want.

View solution in original post

0 Karma

willadams
Contributor

I thought about this some more and the simplest thing to do is probably just create a new status with the codes I want.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...