Splunk Enterprise Security

Splunk Enterprise Security -> Incident Review -> What capability is required to "Edit Selected"

pkeller
Contributor

In the Incident Review panel, we select a Notable Event, click on Edit Selected and a form pops up.
I chose the first dropdown, selected "ACKIN" and clicked on Save and was returned:

Unable to change 1 events: transition from New to ACKIN is not allowed (1 event)

The user has both "edit_reviewstatuses" and "edit_notable_events" yet the error is returned.

alt text

0 Karma
1 Solution

lakshman239
Influencer

I believe you are using custom notable and/or investigation status and the transition status seems to have not been defined. You can review and update them or create new transitions using GUI https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Investigationstatus [ You may need ess_admin or an equivalent role to define]

View solution in original post

0 Karma

lakshman239
Influencer

I believe you are using custom notable and/or investigation status and the transition status seems to have not been defined. You can review and update them or create new transitions using GUI https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Investigationstatus [ You may need ess_admin or an equivalent role to define]

0 Karma

pkeller
Contributor

Thank you very much. I'll look into this.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...