Splunk Enterprise Security

Description for Notable becomes "Success"

NTNS
New Member

I have a fairly hefty search that are looking for potential brute-force attempts in my network. I have verified that the search works and results in a table with the following fields:

end_timereasonsignaturesrcstart_timeusertitle

 

This is completely as I would expect. However, when I try to push the reason into my notable description using $reason$ the resulting notables simple has the word "Success" in their description. I know for a fact that every hit on the search has a fairly descriptive reason, which I can see when I perform the search manually. Pushing the title to the title of the notable works without any problems, even though both appears to be multi value fields, and there should be no difference between them.

I have no idea where to start looking for a solution for this.

Labels (2)
0 Karma

NTNS
New Member

For clarification a reason entry might look like this:

Potential Brute-Force Attack: There were [22] failed attempts and [0] successful login(s) observed from origin [0.0.0.0] towards [ABC] over 2 second(s) between 2023-10-10 10:10:10 and 2023-10-10 10:10:12. Rate: ~11 attempts/s.
Potential Brute-Force Attack: There were [32] failed attempts and [0] successful login(s) observed from origin [1.1.1.1] towards [ABC] over 2 second(s) between 2023-10-10 11:11:01 and 2023-10-10 11:11:03. Rate: ~13 attempts/s.
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...