Splunk Enterprise Security
Highlighted

In Splunk Enterprise Security, how do you change the urgency manually for Incident Review?

Explorer

I am wondering if there is a way to have the urgency of the events just to be how you have it set in the Adaptive Response Actions?

I don't want Incident Review to make it for me. I want to be able to set it myself either with the correlation search or in the Notable Adaptive Response Actions.

0 Karma
Highlighted

Re: In Splunk Enterprise Security, how do you change the urgency manually for Incident Review?

Splunk Employee
Splunk Employee
0 Karma
Highlighted

Re: In Splunk Enterprise Security, how do you change the urgency manually for Incident Review?

Explorer

I looked through that and have tried that but still not working correctly. I am trying to have that be bypassed and have whatever I put into the notable event adaptive response actions to show up in the Incident Review.

0 Karma