Splunk Enterprise Security

How to add link in ES Notable events "next steps" form?

aasabatini
Motivator

Hi Guys,

 

I would ask how to add a link on the next steps form.

on the correlation search I read:

"Add a link to an action with the syntax: [[action|nameOfAction]]."

but is not clear.

Regards

Ale

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”
Labels (1)
0 Karma

rpfutrell
Engager

I've been searching for the same answer, as Splunk ES is is limiting in the regards.  Most our other tools are found elswhere - to expedite the review or mitigation, it would be very helpful to add a link in the next steps to say go to the EDR, the Proofpoint Server, O365 etc... vs. the SOC analyst needing to fumble through his/her bookmarks etc..   If this doesn't exist, I sure how it's on the roadmap. 

0 Karma

lkutch_splunk
Splunk Employee
Splunk Employee

The available response actions are the ones in the dropdown list for "insert adaptive response action." For example if you want the next step to be ping a host, you can use text and the link to the action in that format mentioned: 


Ping a host to determine if it is active on the network. If the host is active, increase the risk score by 100, otherwise, increase the risk score by 50.  [[action|ping]]

https://docs.splunk.com/Documentation/ES/6.6.0/Tutorials/ResponseActionsCorrelationSearch#Part_5:_Ch...

 

Let me know if that helps. 

aasabatini
Motivator

Hi @lkutch_splunk 

Thanks for your reply, yes but my question is:

Can I add for example a clickable confluence link on the "next steps" form? or in the notable event in general?

Thanks

Ale

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”
0 Karma

jvsplunker
Loves-to-Learn Everything

Curious if you were able to put a clickable liink in the "Next Steps" area.

0 Karma

lkutch_splunk
Splunk Employee
Splunk Employee

I don't think it would be a clickable link. It would probably be a copy/paste link.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...