Splunk Enterprise Security

Why are the notable events from Symantec not accurate?

jc_najera
New Member

Hi Community,

Not sure how to explain this... But the whole timeline looks like this:

  1. A user plugs in a USB stick on his machine.
  2. Endopoint protection found a suspicious file on an USB stick. The Antivirus categorized the event as "Left Alone".
  3. Splunk Enterprise Security creates a notable event.
  4. One minute after, the user plugged in the USB again
  5. Again, the antivirus detects the suspicious file, only this time the AV categorizes the event as "Cleaned by deletion"
  6. Splunk Enterprise Security creates a second notable event.

Now we have 2 notable events to investigate, even though the computer, the usb stick and the malicious file are the same.
If the analyst did not have looked for other related events he might have thought that those two alerts were completely unrelated.

Is there a way to group those two notable alerts and "make Splunk" show only the most recent alert of those two?

Thanks

Jose.

0 Karma

maciep
Champion

I think this is what our ES users have been requesting for the past few years now. As of 4.7, I don't think the functionality is there. I'm not sure if they added it in 5.0.

Hopefully since it seems like ITSI can do it, they'll make it available in ES soon.

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...