Splunk Enterprise Security

Why is Splunk ES Contributing Events not seeing many incidents?

burakatabay
Path Finder

Hi splunkers,
My question is Why I not see Contributing Events in All incidents ?
alt text
I want to go directly to the event by pressing the Contributing Events.
alt text
How ı see Contributing Events in all incidents ?
Have a good day.

0 Karma

smoir_splunk
Splunk Employee
Splunk Employee

If the search generating the alert relies on aggregates, there might not be any contributing events to show.

For example, if the search is performing a |stats count and alerting where count>4, it's relying on aggregates of 4 events, it doesn't necessarily keep track of what those 4 specific events were. But if it's alerting on |search threat_intel=calc.exe, there are specific contributing events available. (Examples for illustrative purposes only)

So there are some searches that will have contributing events available, but not all of them do.

burakatabay
Path Finder

Thank you for answer 🙂

0 Karma

TheSplunkDude
Explorer

Also make sure you have a value in the Drill-down Name (and Drill -Down Search) in the Notable event for the correlation search.

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...