Splunk Enterprise Security

Enterprise Security: How can I get the group names I created to populate in the AV logs so an alert can be generated?

chrisschum
Path Finder

In ES, I'm trying to create a correlation search where I establish groups on a 'List and Lookups' asset list (under the Owner column) and if that group matches any critical incidents from our AV, then an alert is generated. However, I cannot get the group names I created to populate in the AV logs so the alert doesn't work.

I've created a Lookup Table, a Lookup Definition and created that .csv list in 'Lists and Lookups' with all necessary rights for all items. However, the data still doesn't populate.

Am I doing something wrong or looking at this in the wrong way?

Thanks!

Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...