Splunk Enterprise Security

How to add link in ES Notable events "next steps" form?

aasabatini
Motivator

Hi Guys,

 

I would ask how to add a link on the next steps form.

on the correlation search I read:

"Add a link to an action with the syntax: [[action|nameOfAction]]."

but is not clear.

Regards

Ale

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”
Labels (1)
0 Karma

rpfutrell
Explorer

It's nice to see that you can now post a URL in ES - thank you!

0 Karma

rpfutrell
Explorer

I've been searching for the same answer, as Splunk ES is is limiting in the regards.  Most our other tools are found elswhere - to expedite the review or mitigation, it would be very helpful to add a link in the next steps to say go to the EDR, the Proofpoint Server, O365 etc... vs. the SOC analyst needing to fumble through his/her bookmarks etc..   If this doesn't exist, I sure how it's on the roadmap. 

0 Karma

lkutch_splunk
Splunk Employee
Splunk Employee

The available response actions are the ones in the dropdown list for "insert adaptive response action." For example if you want the next step to be ping a host, you can use text and the link to the action in that format mentioned: 


Ping a host to determine if it is active on the network. If the host is active, increase the risk score by 100, otherwise, increase the risk score by 50.  [[action|ping]]

https://docs.splunk.com/Documentation/ES/6.6.0/Tutorials/ResponseActionsCorrelationSearch#Part_5:_Ch...

 

Let me know if that helps. 

aasabatini
Motivator

Hi @lkutch_splunk 

Thanks for your reply, yes but my question is:

Can I add for example a clickable confluence link on the "next steps" form? or in the notable event in general?

Thanks

Ale

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”
0 Karma

jvsplunker
Loves-to-Learn Everything

Curious if you were able to put a clickable liink in the "Next Steps" area.

0 Karma

lkutch_splunk
Splunk Employee
Splunk Employee

I don't think it would be a clickable link. It would probably be a copy/paste link.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...