Splunk Enterprise Security

Splunk Security Essentials - Mitre Map does not report each correlation search?

davidem
Explorer

Hi Splunkers,

I have a problem with the "Splunk Security Essentials" application. Currently, I have 34 activated correlation searches that I would like to map on the Mitre Framework.

Viewing the "sse_content_exported_lookup" file, the mitre information does not match the information reported in each correlation rule.

Also, there are correlation searches in the "sse_content_exported_lookup" file that had the mitre but didn't appear in the Mitre Map.

However, all 34 correlation searches show up in the bookmarks.


Could you suggest a solution? is there any procedure I can follow to make sure that all active correlation searches appear in the mitre map?

 

Thank you.

Labels (1)
0 Karma

davidem
Explorer

I noticed that in the file "use_case.csv" ("| sseanalytics | lookup use_cases.csv....") the one from which the data for the mitre map is taken, the data does not match the data in the correlation search, and in particular the field "mitre_tactic_display" is "none".

0 Karma
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...