Splunk Enterprise Security

Splunk ES - How to ddd a Status to Incident Review Dashboard?

sswansonchtr
Path Finder

Under the 'Incident Review' dashboard, I want to add a Status type of 'False Positive' so I can easily find these and use them to help me tune the correlations etc. I found that I can change this lookup file: /splunk/app/splunk/etc/apps/SA-ThreatIntelligence/lookups/reviewstatuses.csv and it will show up correctly in the top fields for searching/filtering. This goes away on a refresh/reload of the service though. Also, editing this file, does not show the new Status type as an option when 'editing' events in the bottom panel.

0 Karma
1 Solution

LukeMurphey
Champion

Use the notable event statuses editor to add a review status. That page will also help you define who and how statuses are allowed to be transitioned.

View solution in original post

LukeMurphey
Champion

Use the notable event statuses editor to add a review status. That page will also help you define who and how statuses are allowed to be transitioned.

sswansonchtr
Path Finder

Thanks for the info. I tried this and it will stay after I refresh/reload splunk but I still don't get an option to label the event as that new status. It only shows up in the filtering options. Not when I select to edit the event. Not sure if it only applied to new notables so I will wait until I get one.

0 Karma

rsteffes
Engager

In case anyone else is unable to see their custom event status in the "Edit Events" menu, you have to edit the existing statuses in the status editor and give user groups authorization to transition the status to your new custom status.

n00b
Explorer

2.5 years later, still useful. This is what I was missing.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...