Splunk Enterprise Security

Enterprise Security: How can I get the group names I created to populate in the AV logs so an alert can be generated?

chrisschum
Path Finder

In ES, I'm trying to create a correlation search where I establish groups on a 'List and Lookups' asset list (under the Owner column) and if that group matches any critical incidents from our AV, then an alert is generated. However, I cannot get the group names I created to populate in the AV logs so the alert doesn't work.

I've created a Lookup Table, a Lookup Definition and created that .csv list in 'Lists and Lookups' with all necessary rights for all items. However, the data still doesn't populate.

Am I doing something wrong or looking at this in the wrong way?

Thanks!

Get Updates on the Splunk Community!

Admin Your Splunk Cloud, Your Way

Join us to maximize different techniques to best tune Splunk Cloud. In this Tech Enablement, you will get ...

Cloud Platform | Discontinuing support for TLS version 1.0 and 1.1

Overview Transport Layer Security (TLS) is a security communications protocol that lets two computers, ...

New Customer Testimonials

Enterprises of all sizes and across different industries are accelerating cloud adoption by migrating ...