Splunk Enterprise Security

New Security Domain

shrutheen
Explorer

I want to add a new Security Domain called "Email" in Enterprise Security (ES) App and later map it to notables. Right now "Threat", "Network", "Identity" are among a few that are available. Is there a way to achieve this ?

0 Karma
1 Solution

skalliger
Motivator

Hi,

yes, you can modify the lookup that is responsible for the available Security Domains (which is also the name of the lookup). Take a look here for an overview of the internal ES lookups: https://docs.splunk.com/Documentation/ES/5.3.1/Admin/Manageinternallookups

Skalli

View solution in original post

skalliger
Motivator

Hi,

yes, you can modify the lookup that is responsible for the available Security Domains (which is also the name of the lookup). Take a look here for an overview of the internal ES lookups: https://docs.splunk.com/Documentation/ES/5.3.1/Admin/Manageinternallookups

Skalli

Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...