- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In Splunk Enterprise Security, how do you change the urgency manually for Incident Review?

HealyManTech
Explorer
11-29-2018
01:24 PM
I am wondering if there is a way to have the urgency of the events just to be how you have it set in the Adaptive Response Actions?
I don't want Incident Review to make it for me. I want to be able to set it myself either with the correlation search or in the Notable Adaptive Response Actions.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

kmorris_splunk

Splunk Employee
11-30-2018
06:48 AM
See the following answers post:
https://answers.splunk.com/answers/481263/how-does-splunk-define-and-assign-urgency-in-splun.html
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

HealyManTech
Explorer
12-03-2018
07:24 AM
I looked through that and have tried that but still not working correctly. I am trying to have that be bypassed and have whatever I put into the notable event adaptive response actions to show up in the Incident Review.
