Splunk Enterprise Security

Enterprise Security: How can I get the group names I created to populate in the AV logs so an alert can be generated?

chrisschum
Path Finder

In ES, I'm trying to create a correlation search where I establish groups on a 'List and Lookups' asset list (under the Owner column) and if that group matches any critical incidents from our AV, then an alert is generated. However, I cannot get the group names I created to populate in the AV logs so the alert doesn't work.

I've created a Lookup Table, a Lookup Definition and created that .csv list in 'Lists and Lookups' with all necessary rights for all items. However, the data still doesn't populate.

Am I doing something wrong or looking at this in the wrong way?

Thanks!

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...