Splunk Enterprise Security

Splunk App for Enterprise Security: After disabling the Google search feature, why is it still an available option in the Incident Review dashboard?

Chubbybunny
Splunk Employee
Splunk Employee

I've disabled the Google search feature in ./SA-ThreatIntelligence/local/workflow_actions.conf and confirmed it is no longer a selectable feature in the ES Search UI and throughout, however, I still see it as an available option in the IR DB (Incident Review dashboard). Am I missing another conf file or setting outside of workflow?

current settings:

./SA-ThreatIntelligence/local/workflow_actions.conf
    [Google]
    disabled = True
    display_location = field_menu
    fields = *
    label = Google $@field_value$
    link.method = get
    link.uri = http://www.google.com/search?q=$@field_value$
    type = link 
1 Solution

Chubbybunny
Splunk Employee
Splunk Employee

This is a bug in ES 3.2.1, reported in SOLNESS-6376

Workaround: remove the asterisk in the 'fields' setting and replace it with random text.

./SA-ThreatIntelligence/local/workflow_actions.conf
[Google]
disabled = True
display_location = field_menu
fields = XXXXXXXX
label = Google $@field_value$
link.method = get
link.uri = http://www.google.com/search?q=$@field_value$
type = link

save the changes and restart splunkd

View solution in original post

Chubbybunny
Splunk Employee
Splunk Employee

This is a bug in ES 3.2.1, reported in SOLNESS-6376

Workaround: remove the asterisk in the 'fields' setting and replace it with random text.

./SA-ThreatIntelligence/local/workflow_actions.conf
[Google]
disabled = True
display_location = field_menu
fields = XXXXXXXX
label = Google $@field_value$
link.method = get
link.uri = http://www.google.com/search?q=$@field_value$
type = link

save the changes and restart splunkd

Get Updates on the Splunk Community!

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...

Explore the Latest Educational Offerings from Splunk (November Releases)

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

New This Month in Splunk Observability Cloud - Metrics Usage Analytics, Enhanced K8s ...

The latest enhancements across the Splunk Observability portfolio deliver greater flexibility, better data and ...