Splunk Enterprise Security

Risk Analysis Dashboard - Risk Modifiers by Annotations

mjuestel2
Path Finder

Hello:

I recently started playing with the Risk framework, RBA etc. Most of my Risk Analysis dashboard is working within Enterprise Security - except for three (3) sections:

 

  • Risk Modifiers By Annotations
  • Risk Score By Annotations
  • Risk Modifiers By Threat Object

 

For the annotations part - we do manually tag Mitre Attack tactics within our content, so not sure why these panels do not show anything.

Also, does anyone know what savedsearches run in the background to populate these panels? I'd like to double check to make sure I have these enabled.

 

Thanks!

 

 

 

 

0 Karma

meetmshah
SplunkTrust
SplunkTrust

Hello @mjuestel2,

The annotations Dashboard would be based on the MITRE Technique value we provide in the correlation searches. Also, it's not savedsearches based on which panels work upon - it's the Risk Data Model - 

meetmshah_0-1697177595409.png

 

Please let me know if you have any questions about the same. Also, please accept the solution and hit Karma, if this helps!

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...