Splunk Enterprise Security

Description for Notable becomes "Success"

NTNS
New Member

I have a fairly hefty search that are looking for potential brute-force attempts in my network. I have verified that the search works and results in a table with the following fields:

end_timereasonsignaturesrcstart_timeusertitle

 

This is completely as I would expect. However, when I try to push the reason into my notable description using $reason$ the resulting notables simple has the word "Success" in their description. I know for a fact that every hit on the search has a fairly descriptive reason, which I can see when I perform the search manually. Pushing the title to the title of the notable works without any problems, even though both appears to be multi value fields, and there should be no difference between them.

I have no idea where to start looking for a solution for this.

Labels (2)
0 Karma

NTNS
New Member

For clarification a reason entry might look like this:

Potential Brute-Force Attack: There were [22] failed attempts and [0] successful login(s) observed from origin [0.0.0.0] towards [ABC] over 2 second(s) between 2023-10-10 10:10:10 and 2023-10-10 10:10:12. Rate: ~11 attempts/s.
Potential Brute-Force Attack: There were [32] failed attempts and [0] successful login(s) observed from origin [1.1.1.1] towards [ABC] over 2 second(s) between 2023-10-10 11:11:01 and 2023-10-10 11:11:03. Rate: ~13 attempts/s.
0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...