Splunk Enterprise Security

Splunk App for Enterprise Security: After disabling the Google search feature, why is it still an available option in the Incident Review dashboard?

Chubbybunny
Splunk Employee
Splunk Employee

I've disabled the Google search feature in ./SA-ThreatIntelligence/local/workflow_actions.conf and confirmed it is no longer a selectable feature in the ES Search UI and throughout, however, I still see it as an available option in the IR DB (Incident Review dashboard). Am I missing another conf file or setting outside of workflow?

current settings:

./SA-ThreatIntelligence/local/workflow_actions.conf
    [Google]
    disabled = True
    display_location = field_menu
    fields = *
    label = Google $@field_value$
    link.method = get
    link.uri = http://www.google.com/search?q=$@field_value$
    type = link 
1 Solution

Chubbybunny
Splunk Employee
Splunk Employee

This is a bug in ES 3.2.1, reported in SOLNESS-6376

Workaround: remove the asterisk in the 'fields' setting and replace it with random text.

./SA-ThreatIntelligence/local/workflow_actions.conf
[Google]
disabled = True
display_location = field_menu
fields = XXXXXXXX
label = Google $@field_value$
link.method = get
link.uri = http://www.google.com/search?q=$@field_value$
type = link

save the changes and restart splunkd

View solution in original post

Chubbybunny
Splunk Employee
Splunk Employee

This is a bug in ES 3.2.1, reported in SOLNESS-6376

Workaround: remove the asterisk in the 'fields' setting and replace it with random text.

./SA-ThreatIntelligence/local/workflow_actions.conf
[Google]
disabled = True
display_location = field_menu
fields = XXXXXXXX
label = Google $@field_value$
link.method = get
link.uri = http://www.google.com/search?q=$@field_value$
type = link

save the changes and restart splunkd

Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...