Hello,
I must be really tired. Cannot find the Add New Response Action, which is part of setting up my new ES. Can anyone help?
Thank You!
If you click on a Correlation Search (for example) such as (chosen at random) "ESCU - Detect Windows DNS SIGRed via Splunk Stream - Rule"... you can scroll down to Adaptive Response Actions and click +Add New Response Action.
So that's under Configure -> Content -> Content Management -> <name of correlation search>
If you click on a Correlation Search (for example) such as (chosen at random) "ESCU - Detect Windows DNS SIGRed via Splunk Stream - Rule"... you can scroll down to Adaptive Response Actions and click +Add New Response Action.
So that's under Configure -> Content -> Content Management -> <name of correlation search>