Splunk Enterprise Security

Need to pull all the data from the investigation panel (Enterprise Security) and send to third party (Archer, ServiceNow) via API

ajaylowes
Path Finder

Need to pull all the data from the investigation panel (Enterprise Security) and send to third party (Archer, ServiceNow) via API

For starters, i need to pull the information from the investigation panel so that i can run the python script to push the data to the API.

0 Karma

LukeMurphey
Champion
0 Karma

ajaylowes
Path Finder

@LukeMurphey For some strange reason, i dont see any event_id in my notable index.
Secondly, i want to fetch the notable info(not update the notable).

Can you please help me out

0 Karma

lakshman239
Influencer

if you run the notable macro search, you should see rule_id and event_id [ they are the same fields]

`notable` | table _time , source, event_id, rule_id
0 Karma

lakshman239
Influencer

Thanks @LukeMurphey for the links, but not seeing info related to Investigations performed against notables. Am I missing something?

0 Karma

LukeMurphey
Champion

I might have mistakenly assumed that "investigation" was a reference to a notable. If so, then my answer is incorrect.

@ajaylowes: could you clarify if you mean a notable event (what you see on Incident Review) or an investigation (what you see on the "Investigations" page)?

0 Karma

ajaylowes
Path Finder

@LukeMurphey This is what we see on the "investigation" page

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...