Splunk Enterprise Security

Threat Activity Detected Notable not triggered

b_chris21
Communicator

Hello everyone,

I have added an IP on local_intel_ip.csv and it now appears on Threat Artifact panel. The correlation search "Threat Activity Detected" is enabled with Adaptive Response Actions a Notable and Risk Analysis.

A notable event was triggered with this IP as destination IP, but the aforementioned Notable (Threat Activity Detected) was never triggered. 

Any idea on what I might have done wrong?

Thank you in advance.

Chris

Labels (2)
Tags (1)
0 Karma
1 Solution

b_chris21
Communicator

After troubleshooting I found the solution: 

I had the Acceleration of Alerts datamodel disabled. Once enabled, the alerts started popping up to my Incident Review console.

View solution in original post

0 Karma

b_chris21
Communicator

After troubleshooting I found the solution: 

I had the Acceleration of Alerts datamodel disabled. Once enabled, the alerts started popping up to my Incident Review console.

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise Security 8.0!

Join us on Wednesday, November 20 to learn about Splunk Enterprise Security 8.0!To enhance SOC efficiency, ...

Mastering Threat Hunting

Register to watch Mastering Threat Hunting on Monday, November 18Join us for an insightful talk where we dive ...

Upcoming Community Maintenance: 10/28

Howdy folks, just popping in to let you know that the Splunk Community site will be in read-only mode ...