Splunk Enterprise Security

Add custom tag on close of ES Incident

willadams
Contributor

We have a number of correlation searches that trigger in Enterprise Security. From these events that trigger in IR, some events are true positive others are not. What I am trying to do is have my analysts mark the notable event with something like a tag to indicate whether the alert was a true positive or not. At the moment, the only way I have been able to do this is have the analyst type this in the closing comments of an event. This would work perfectly fine, except that this requires an analyst to (1) remember, (2) put it in the right format (i.e. someone may type is false positive or fp or false-positive etc.) and (3) put it in the same spot.

Is there a way in Incident Review (via the incident_review index) to populate additional information when an event is closed with a tag about the event. I am not sure if this can be added as an action (as opposed to an adaptive invocation action). While Security Posture provides me a count of a particular notable event, I would like to extend this beyond just the count (i.e. notable event number but how many were false positives, how many were true positives, etc...)

0 Karma
1 Solution

willadams
Contributor

I thought about this some more and the simplest thing to do is probably just create a new status with the codes I want.

View solution in original post

0 Karma

willadams
Contributor

I thought about this some more and the simplest thing to do is probably just create a new status with the codes I want.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...