Splunk Enterprise Security

What populates the list of "Owners" in the ES App?

vanderaj2
Path Finder

Hey Splunkers,

I'd like to assign an owner to some events appearing in the 'Incident Review" dashboard in the Enterprise Security App.

However, I only see a few users appearing in the "Owner" drop-down list. Some users I'd like to assign the events to as Owners are not in this drop-down list.

Does anyone know what populates the Owners list? Is there some lookup table somewhere? LDAP? Other?

Thanks!

1 Solution

smoir_splunk
Splunk Employee
Splunk Employee

The notable_owners_lookup is populated by the Threat - Notable Owners - Lookup Gen saved search. The list is limited by those that have the capability to own notable events, and if you use SAML authentication with ES, the list can take some time to populate. Check to see if all of the users you expect to see in the list have the capability to own notable events.

View solution in original post

smoir_splunk
Splunk Employee
Splunk Employee

The notable_owners_lookup is populated by the Threat - Notable Owners - Lookup Gen saved search. The list is limited by those that have the capability to own notable events, and if you use SAML authentication with ES, the list can take some time to populate. Check to see if all of the users you expect to see in the list have the capability to own notable events.

vanderaj2
Path Finder

Perfect. That was the answer - thank you! I had to make sure the right users had the capability to own notable events, and I noticed that somebody had disabled the "Threat - Notable Owners - Lookup Gen" saved search. Once I added the correct capability and ran the saved search, the lookup table updated with the other users I was expecting to see.

0 Karma

smoir_splunk
Splunk Employee
Splunk Employee

I'm glad that fixed it! It's also worth noting that most of the lookup gen searches are performing useful internal tasks like this, and when making the effort to reduce the number of searches running overall, it's useful to dig into what the searches are doing before disabling them.

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...