Splunk Enterprise Security

Notable urgency not registering correctly

ebs
Communicator

Hi,

According to the Splunk Docs page How urgency is assigned to notable events in Splunk Enterprise Security if I assign an asset Medium priority and High severity in the related Correlation Search (CS) it should register as a High Notable, however it still persists to register as a Medium causing me to up the Severity to Critical. Has there been a change in how ES operates where the table as written no longer works or is there something wrong with the ES instance? Also its Splunk Cloud

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @ebs,

Did you check if your Urgency Lookup is modified? 

https://docs.splunk.com/Documentation/ES/6.4.1/User/Howurgencyisassigned#Modify_the_urgency_lookup_d...

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

ebs
Communicator

I just checked and it seems to be unaltered

0 Karma

p_gurav9491
Loves-to-Learn Everything

Is this issue got resolved? we are facing similar issue where priority is unknown and  severity is critical, according to matrix it should trigger high notables but its triggering low and medium notables also.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...