Splunk Enterprise Security

How to resolve Threat Artifacts report false postives in Threat Activity

Azeemering
Builder

An Example:
We have defined two malicious urls in the local_http_intel

Azeemering_0-1658236628839.png

This triggers false positives in the Threat Activity of ES on the valid and safe domain of github.com

Azeemering_1-1658236731069.png

How can we prevent / fix this?

0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Cloud Platform 9.3.2411?

Hey Splunky People! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2411. This release ...

Buttercup Games: Further Dashboarding Techniques (Part 6)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...