Splunk Enterprise Security

Notable events ES

aasabatini
Builder

Hi Folks,

I have one question, it's possible add an response action when the notable event change status?

Example:

I have my notable event on open status, when the analyst change the status to assigned, trigger the adaptive response action (service now incident creation).

Labels (1)
0 Karma