Splunk Enterprise Security
Highlighted

Splunk Enterprise Security -> Incident Review -> What capability is required to "Edit Selected"

Contributor

In the Incident Review panel, we select a Notable Event, click on Edit Selected and a form pops up.
I chose the first dropdown, selected "ACKIN" and clicked on Save and was returned:

Unable to change 1 events: transition from New to ACKIN is not allowed (1 event)

The user has both "editreviewstatuses" and "editnotable_events" yet the error is returned.

alt text

0 Karma
Highlighted

Re: Splunk Enterprise Security -> Incident Review -> What capability is required to "Edit Selected"

SplunkTrust
SplunkTrust

I believe you are using custom notable and/or investigation status and the transition status seems to have not been defined. You can review and update them or create new transitions using GUI https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Investigationstatus [ You may need ess_admin or an equivalent role to define]

View solution in original post

0 Karma
Highlighted

Re: Splunk Enterprise Security -> Incident Review -> What capability is required to "Edit Selected"

Contributor

Thank you very much. I'll look into this.

0 Karma