Splunk Enterprise Security

Enterprise Security: How can I get the group names I created to populate in the AV logs so an alert can be generated?

chrisschum
Path Finder

In ES, I'm trying to create a correlation search where I establish groups on a 'List and Lookups' asset list (under the Owner column) and if that group matches any critical incidents from our AV, then an alert is generated. However, I cannot get the group names I created to populate in the AV logs so the alert doesn't work.

I've created a Lookup Table, a Lookup Definition and created that .csv list in 'Lists and Lookups' with all necessary rights for all items. However, the data still doesn't populate.

Am I doing something wrong or looking at this in the wrong way?

Thanks!

Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!