Splunk Enterprise Security

Setting Multiple severity level for same Correlation search

Shradha_Venkata
New Member

Hi,

Is it possible to set two different severity level for same Correlation search.

For Eg
My search output list source that are communicating to blacklisted IPs
I have set the severity level as high in notable event of the search. But i want to include one more severity level as "informational" for few IPs.

Thanks

0 Karma

jstoner_splunk
Splunk Employee
Splunk Employee

Within the correlation search you may be able to use an eval command with something like a case statement to do this. However, if you have a list of IPs, I am hoping that there is a second column that has a descriptor like high severity ip and low severity ip. That way the case statement could look for one of the other and assign an urgency based on that value. I have not tested that, but something along those lines should work.

This example we forced an urgency in for reference: https://answers.splunk.com/answers/495073/splunk-enterprise-security-is-there-a-way-to-force.html#an...

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...