Splunk Enterprise Security

Why aren't Risk Score, Risk Event and Risk Object showing in the notable event?

syazwani
Path Finder

Hi peeps,

We were fine tuning the Notable Event, and there were fields that were not showing any values. Those fields are the Risk Score, Risk Event and Risk Object. We have configure the value under the Risk Analysis Tab. 

WhatsApp Image 2022-09-07 at 15.00.21.jpeg

WhatsApp Image 2022-09-07 at 15.01.06.jpeg

Please assist us on this. Thank you.

0 Karma

roberto_baggio
Explorer

Hey so did you find the solution? We stacked with the same issue and seams no one knows how to fix it. 

0 Karma

travis_lelle
Explorer

Have you found a solution for this? I'm experiencing the same thing, and I made sure that the fields we provided in the Risk Analysis Adaptive response Action is a valid field that is being presented in the correlation search results. In fact, I'm using the same fields as variables in the title of the notable event. But nothing is populating in Incident review for Risk Score, Risk Event, and Risk Object.

0 Karma

hettervik
Builder

Hi. Yes, I see the confusion. The fields you add under the response action "Risk Analysis" are not added the the notable event itself (index=notable), they are added to the risk event (index=risk). These risk events are used for Risk-Based Alerting, among other things.

If you want the "user" and "app" fields to be added to the notable event, just make sure these fields are present in the final output of your correlation search, and you shoud see them in the incident.

0 Karma
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...