- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

sheamus69
Communicator
05-25-2016
02:08 AM
Is it possible to add the risk scores to the notable events listed in Incident Review?
I think it's possible to achieve this with UBA, but I don't have UBA and am unlikely to have it in the short to medium term.
What I would like to do is have the risk scores for a notable event logged in incident review as one of the columns.
Is this possible?
We're running Splunk Enterprise Security 4.0.1.
Thanks for the assistance,
Sheamus
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

sheamus69
Communicator
05-31-2016
06:01 AM
It looks as if this is a feature of ES 4.1, so I will need to upgrade ES to test this out.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

sheamus69
Communicator
05-31-2016
06:01 AM
It looks as if this is a feature of ES 4.1, so I will need to upgrade ES to test this out.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

sheamus69
Communicator
06-24-2016
02:07 AM
Just to confirm, this was the case.
