Splunk Enterprise Security

How to set Notable Event Status Via Search?

splunkbunk
Explorer

Hi All,

Recently a question came up about notifying a client on high urgency notable events. I want to send out an auto email anytime there's a high urgency notable event. It's easy to write a search that checks for high urgency notable events and send an email. However, I also want to be able to change the status of these notables within the same search as I send the email (Client Notified, or something similar). Is there a simple way to do this? I'd even settle for a complicated way 🙂

Thanks for reading!

0 Karma

meetmshah
Communicator

Hello @splunkbunk, You can update the urgency under incident_review_lookup once you run the saved search that notifies users.

0 Karma
Get Updates on the Splunk Community!

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...

Cloud Platform | Migrating your Splunk Cloud deployment to Python 3.7

Python 2.7, the last release of Python 2, reached End of Life back on January 1, 2020. As part of our larger ...

Splunk Observability Cloud | Enhancing Your Onboarding Experience with the ...

We understand that your initial experience with getting data into Splunk Observability Cloud is crucial as it ...