Splunk Enterprise Security

Enterprise Security Suite Incident Review - How do you edit the owners list?

vaudajordan
Engager

How do you control who is in the drop down list of owners, so you can assign a ticket to someone else? It seems to have picked a bunch of random people and not the two people I need in there.

Labels (1)
1 Solution

LukeMurphey
Champion

Make sure that the users you want to assign notable events to have the "can_own_notable_events" capability. Once you add that, you should see them in the list of people you can assign notable events to in a few minutes.

View solution in original post

lmyrefelt
Builder

I belive your users need to be member of the "Security Analyst" (dont remmember the "correct" name) role

Read the docs, it is described in there how to setup / configure it correctly. 😉

0 Karma

LukeMurphey
Champion

Make sure that the users you want to assign notable events to have the "can_own_notable_events" capability. Once you add that, you should see them in the list of people you can assign notable events to in a few minutes.

aakwah
Builder

The problem with this solution is that all Admins have the capability "can_own_notable_events" and they appear in the list among SOC analysts.

The woraround I found is to disable "es_notable_events" in Lookup definitions page, and edit the kv-store lookup "notable_owners" by the app "Splunk App for Lookup File Editing".

The impact of this solution is that newly added SOC members need to be added manually to the "notable_owners" lookup.

 

First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...