Splunk Enterprise Security

Description for Notable becomes "Success"

NTNS
New Member

I have a fairly hefty search that are looking for potential brute-force attempts in my network. I have verified that the search works and results in a table with the following fields:

end_timereasonsignaturesrcstart_timeusertitle

 

This is completely as I would expect. However, when I try to push the reason into my notable description using $reason$ the resulting notables simple has the word "Success" in their description. I know for a fact that every hit on the search has a fairly descriptive reason, which I can see when I perform the search manually. Pushing the title to the title of the notable works without any problems, even though both appears to be multi value fields, and there should be no difference between them.

I have no idea where to start looking for a solution for this.

Labels (2)
0 Karma

NTNS
New Member

For clarification a reason entry might look like this:

Potential Brute-Force Attack: There were [22] failed attempts and [0] successful login(s) observed from origin [0.0.0.0] towards [ABC] over 2 second(s) between 2023-10-10 10:10:10 and 2023-10-10 10:10:12. Rate: ~11 attempts/s.
Potential Brute-Force Attack: There were [32] failed attempts and [0] successful login(s) observed from origin [1.1.1.1] towards [ABC] over 2 second(s) between 2023-10-10 11:11:01 and 2023-10-10 11:11:03. Rate: ~13 attempts/s.
0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...