Splunk Enterprise Security

Why aren't Risk Score, Risk Event and Risk Object showing in the notable event?

syazwani
Path Finder

Hi peeps,

We were fine tuning the Notable Event, and there were fields that were not showing any values. Those fields are the Risk Score, Risk Event and Risk Object. We have configure the value under the Risk Analysis Tab. 

WhatsApp Image 2022-09-07 at 15.00.21.jpeg

WhatsApp Image 2022-09-07 at 15.01.06.jpeg

Please assist us on this. Thank you.

0 Karma

roberto_baggio
Explorer

Hey so did you find the solution? We stacked with the same issue and seams no one knows how to fix it. 

0 Karma

travis_lelle
Explorer

Have you found a solution for this? I'm experiencing the same thing, and I made sure that the fields we provided in the Risk Analysis Adaptive response Action is a valid field that is being presented in the correlation search results. In fact, I'm using the same fields as variables in the title of the notable event. But nothing is populating in Incident review for Risk Score, Risk Event, and Risk Object.

0 Karma

hettervik
Builder

Hi. Yes, I see the confusion. The fields you add under the response action "Risk Analysis" are not added the the notable event itself (index=notable), they are added to the risk event (index=risk). These risk events are used for Risk-Based Alerting, among other things.

If you want the "user" and "app" fields to be added to the notable event, just make sure these fields are present in the final output of your correlation search, and you shoud see them in the incident.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...