Splunk Enterprise Security

Splunk Enterprise Security -> Incident Review -> What capability is required to "Edit Selected"

pkeller
Contributor

In the Incident Review panel, we select a Notable Event, click on Edit Selected and a form pops up.
I chose the first dropdown, selected "ACKIN" and clicked on Save and was returned:

Unable to change 1 events: transition from New to ACKIN is not allowed (1 event)

The user has both "edit_reviewstatuses" and "edit_notable_events" yet the error is returned.

alt text

0 Karma
1 Solution

lakshman239
Influencer

I believe you are using custom notable and/or investigation status and the transition status seems to have not been defined. You can review and update them or create new transitions using GUI https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Investigationstatus [ You may need ess_admin or an equivalent role to define]

View solution in original post

0 Karma

Pranav_Support
New Member

Adding the 'ess_user' Role:

To edit and create a new 'Incident Review' while still in the 'user' role, you need to add the 'ess_user' role to your current user role. This is necessary because we have set capabilities related to 'ess_user', which are required for this task.

The 'ess_user' should be given the following capabilities:

- edit_notable_events: This allows the role to create new (ad-hoc) Notable Events and edit existing ones.
- edit_log_review_settings: This permits the role to edit Incident Review settings.

By adding these capabilities, you should be able to edit and create a new 'Incident Review'.

Configuring Permissions in Splunk Enterprise Security:

This can be done by navigating to Configure -> General -> Permission in Splunk Enterprise Security. Ensure the 'ess_user' is given the following permissions:

- Create New Notable Events
- Edit Incident Review
- Edit Notable Events

Note: The 'ess_analyst' role can be directly assigned to a user, enabling them to manage Incident Review dashboards. A user with 'ess_analyst' must be able to edit notable events.

0 Karma

lakshman239
Influencer

I believe you are using custom notable and/or investigation status and the transition status seems to have not been defined. You can review and update them or create new transitions using GUI https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Investigationstatus [ You may need ess_admin or an equivalent role to define]

0 Karma

pkeller
Contributor

Thank you very much. I'll look into this.

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...