I have read this article which describes searching for high or critical notable events.
https://answers.splunk.com/answers/432018/splunk-enterprise-security-how-to-set-up-alerts-wh.html
notable
| where urgency="high" OR urgency="critical" | table _time source src dest user | eval computer=coalesce(src,dest)
Now i need a simple way to create a critical notable event to test.
How best to achieve this ?
gratzi
You can also create a manual notable event in the UI. https://docs.splunk.com/Documentation/ES/4.7.2/Admin/Createnotablesmanually
I had to do something like this today try the following:
| makeresults
| eval user="skins", urgency="critical"
| sendalert notable