Splunk Enterprise Security

Splunk App for Enterprise Security: After disabling the Google search feature, why is it still an available option in the Incident Review dashboard?

Chubbybunny
Splunk Employee
Splunk Employee

I've disabled the Google search feature in ./SA-ThreatIntelligence/local/workflow_actions.conf and confirmed it is no longer a selectable feature in the ES Search UI and throughout, however, I still see it as an available option in the IR DB (Incident Review dashboard). Am I missing another conf file or setting outside of workflow?

current settings:

./SA-ThreatIntelligence/local/workflow_actions.conf
    [Google]
    disabled = True
    display_location = field_menu
    fields = *
    label = Google $@field_value$
    link.method = get
    link.uri = http://www.google.com/search?q=$@field_value$
    type = link 
1 Solution

Chubbybunny
Splunk Employee
Splunk Employee

This is a bug in ES 3.2.1, reported in SOLNESS-6376

Workaround: remove the asterisk in the 'fields' setting and replace it with random text.

./SA-ThreatIntelligence/local/workflow_actions.conf
[Google]
disabled = True
display_location = field_menu
fields = XXXXXXXX
label = Google $@field_value$
link.method = get
link.uri = http://www.google.com/search?q=$@field_value$
type = link

save the changes and restart splunkd

View solution in original post

Chubbybunny
Splunk Employee
Splunk Employee

This is a bug in ES 3.2.1, reported in SOLNESS-6376

Workaround: remove the asterisk in the 'fields' setting and replace it with random text.

./SA-ThreatIntelligence/local/workflow_actions.conf
[Google]
disabled = True
display_location = field_menu
fields = XXXXXXXX
label = Google $@field_value$
link.method = get
link.uri = http://www.google.com/search?q=$@field_value$
type = link

save the changes and restart splunkd

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...