Splunk Enterprise Security

Splunk ES Drill-Down- How do I receive 2 separate notable alerts?

LIP
Loves-to-Learn

I created the following correlation alerts in ES with Notable

Index=fw (dest_ip=1.2.3.4 OR dest_ip=1.2.3.5)

The alerts in with cron for every 1M

Example:

At 08:00, User A ping 1.2.3.4
At 08:00, User B ping 1.2.3.3

 

The problem:

If two different users try to get these IPs, I will receive two notable alerts with a drill down. The drill-down will bring the two events from these two different users (mix).

What I expect to receive: 2 separate notable alerts with drill down that will receive only one event (and not the events from the other user)

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Modify the notable to include the User field ($User$) in the drilldown.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...