Splunk Enterprise Security

Splunk Security Essentials - Mitre Map does not report each correlation search?

davidem
Explorer

Hi Splunkers,

I have a problem with the "Splunk Security Essentials" application. Currently, I have 34 activated correlation searches that I would like to map on the Mitre Framework.

Viewing the "sse_content_exported_lookup" file, the mitre information does not match the information reported in each correlation rule.

Also, there are correlation searches in the "sse_content_exported_lookup" file that had the mitre but didn't appear in the Mitre Map.

However, all 34 correlation searches show up in the bookmarks.


Could you suggest a solution? is there any procedure I can follow to make sure that all active correlation searches appear in the mitre map?

 

Thank you.

Labels (1)
0 Karma

davidem
Explorer

I noticed that in the file "use_case.csv" ("| sseanalytics | lookup use_cases.csv....") the one from which the data for the mitre map is taken, the data does not match the data in the correlation search, and in particular the field "mitre_tactic_display" is "none".

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...