- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk Enterprise Security: Is it possible to automate assignment of notable events to groups?
rahul130191
New Member
04-04-2016
09:01 PM
Is it possible to automate assignment of notable events to groups?
For example, if a new notable event is triggered, is there a way to automatically assign it to a created group like to the L1 team?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ryandg
Communicator
04-14-2016
06:54 AM
What do you mean by group? A specific role? You could always create a custom notable event status called "Assigned to L1 Team" that is the default status for the notable events. You can't assign a notable event to a role though as far as I am aware so this would be the best work around I can think of.
