Splunk Enterprise Security

How to set Notable Event Status Via Search?

splunkbunk
Explorer

Hi All,

Recently a question came up about notifying a client on high urgency notable events. I want to send out an auto email anytime there's a high urgency notable event. It's easy to write a search that checks for high urgency notable events and send an email. However, I also want to be able to change the status of these notables within the same search as I send the email (Client Notified, or something similar). Is there a simple way to do this? I'd even settle for a complicated way 🙂

Thanks for reading!

0 Karma

meetmshah
Builder

Hello @splunkbunk, You can update the urgency under incident_review_lookup once you run the saved search that notifies users.

0 Karma
Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...