Splunk Enterprise Security

Security Posture: Notable Events By Urgency

rhoush
Observer

Under the Security posture there is a "Notable Events By Urgency" chart but it only shows medium, low and informational. I need to report High and critical notable events.

Why doesn't the chart show all categories of urgency?

0 Karma

jawaharas
Motivator

The query under 'Notable Events By Urgency' panel is not filtering events by severity.

Query used in the panel:

| `es_notable_events` | search timeDiff_type=current | stats sum(count) as count by urgency | `stats2chart("urgency")`

Tip: Press Ctrl + Shift + E (in Windows) to expand the macro in the query.

If the notable events (including 'High' and 'Critical' ones) exists in the lookup table es_notable_events, you can see them under the 'Notable Events By Urgency' panel

0 Karma

jawaharas
Motivator

@rhoush
If my answer helped you, please accept and/or upvote it!

0 Karma

rhoush
Observer

Version is 5.3.0 Build 9

0 Karma

smoir_splunk
Splunk Employee
Splunk Employee

What version of ES do you have? It shows data from the last 24 hours, so if you don't have any notables that are high or critical from the last 24 hours of data, they might not appear. It should show all categories of urgency, but only if there is >0 results for them.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...