Splunk Enterprise Security

What populates the list of "Owners" in the ES App?

vanderaj2
Path Finder

Hey Splunkers,

I'd like to assign an owner to some events appearing in the 'Incident Review" dashboard in the Enterprise Security App.

However, I only see a few users appearing in the "Owner" drop-down list. Some users I'd like to assign the events to as Owners are not in this drop-down list.

Does anyone know what populates the Owners list? Is there some lookup table somewhere? LDAP? Other?

Thanks!

1 Solution

smoir_splunk
Splunk Employee
Splunk Employee

The notable_owners_lookup is populated by the Threat - Notable Owners - Lookup Gen saved search. The list is limited by those that have the capability to own notable events, and if you use SAML authentication with ES, the list can take some time to populate. Check to see if all of the users you expect to see in the list have the capability to own notable events.

View solution in original post

smoir_splunk
Splunk Employee
Splunk Employee

The notable_owners_lookup is populated by the Threat - Notable Owners - Lookup Gen saved search. The list is limited by those that have the capability to own notable events, and if you use SAML authentication with ES, the list can take some time to populate. Check to see if all of the users you expect to see in the list have the capability to own notable events.

vanderaj2
Path Finder

Perfect. That was the answer - thank you! I had to make sure the right users had the capability to own notable events, and I noticed that somebody had disabled the "Threat - Notable Owners - Lookup Gen" saved search. Once I added the correct capability and ran the saved search, the lookup table updated with the other users I was expecting to see.

0 Karma

smoir_splunk
Splunk Employee
Splunk Employee

I'm glad that fixed it! It's also worth noting that most of the lookup gen searches are performing useful internal tasks like this, and when making the effort to reduce the number of searches running overall, it's useful to dig into what the searches are doing before disabling them.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...