Splunk Enterprise Security

Threat Activity Detected Notable not triggered

b_chris21
Communicator

Hello everyone,

I have added an IP on local_intel_ip.csv and it now appears on Threat Artifact panel. The correlation search "Threat Activity Detected" is enabled with Adaptive Response Actions a Notable and Risk Analysis.

A notable event was triggered with this IP as destination IP, but the aforementioned Notable (Threat Activity Detected) was never triggered. 

Any idea on what I might have done wrong?

Thank you in advance.

Chris

Labels (2)
Tags (1)
0 Karma
1 Solution

b_chris21
Communicator

After troubleshooting I found the solution: 

I had the Acceleration of Alerts datamodel disabled. Once enabled, the alerts started popping up to my Incident Review console.

View solution in original post

0 Karma

b_chris21
Communicator

After troubleshooting I found the solution: 

I had the Acceleration of Alerts datamodel disabled. Once enabled, the alerts started popping up to my Incident Review console.

0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...