Splunk Enterprise Security

Splunk 'Enterprise Security Suite' - Identity Management's Priority calculation

jawaharas
Motivator

Configuration:
We have configured a lookup table under 'ESS Identity management' to maintain the list of users. The user list is updated daily using a scheduled search. And the 'priority' of the user is calculated either as 'high' or 'medium' based on certain factors.

Problem:
But, the priority of a few users is modified as 'critical'. I am trying to understand feature/search which modifies the priority value.

Any help is a welcome one. Thanks.

0 Karma
1 Solution

lakshman239
Influencer

I don't think the users priority in the identity tables gets changed by any other process. Can you pls double check if your scheduled search is updating it? (perhaps)
I assume you are not talking about -https://docs.splunk.com/Documentation/ES/5.2.2/User/Howurgencyisassigned

View solution in original post

0 Karma

lakshman239
Influencer

I don't think the users priority in the identity tables gets changed by any other process. Can you pls double check if your scheduled search is updating it? (perhaps)
I assume you are not talking about -https://docs.splunk.com/Documentation/ES/5.2.2/User/Howurgencyisassigned

0 Karma

jawaharas
Motivator

You are right. I have overlooked the scheduled search that updates the identity lookup table. My bad.

The priority indeed calculated and updated by the scheduled search. Thanks.

0 Karma

lakshman239
Influencer

If you are happy with the answer, pls accept the same to close the thread.

0 Karma
Get Updates on the Splunk Community!

Get Schooled with Splunk Education: Explore Our Latest Courses

At Splunk Education, we’re dedicated to providing incredible learning experiences that cater to every skill ...

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL  The Splunk AI Assistant for SPL ...

Buttercup Games: Further Dashboarding Techniques (Part 5)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...