Splunk Enterprise Security

Splunk Enterprise Security: Is it possible to automate assignment of notable events to groups?

rahul130191
New Member

Is it possible to automate assignment of notable events to groups?

For example, if a new notable event is triggered, is there a way to automatically assign it to a created group like to the L1 team?

0 Karma

ryandg
Communicator

What do you mean by group? A specific role? You could always create a custom notable event status called "Assigned to L1 Team" that is the default status for the notable events. You can't assign a notable event to a role though as far as I am aware so this would be the best work around I can think of.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...