Splunk Enterprise Security

Why not getting Notables?

timsheets13
Loves-to-Learn

I'm new to ES.  I have taken the ES Admin course so I probably shouldn't have to ask for help but I'm pulling my hair out.

I have a linux host running sshd, no firewall.  This host has the universal forwarder sending events to the index cluster.

I have another linux host running a brute force attack against it.

Search in Splunk clearly shows the failed attempts, thousands of them.

In ES, I have enabled the "Brute Force Access Behavior Detected" correlation search, and added a Adaptive Response Action to create notable.

However, even though there are thousands of matching events, I never get a notable created.

SA_AccessProtection app is installed.

Any ideas of how to troubleshoot this, or what might be wrong greatly appreciated.

 

Labels (2)
Tags (1)
0 Karma

tscroggins
SplunkTrust
SplunkTrust

@timsheets13 

Does the "notable" index exist?

0 Karma

timsheets13
Loves-to-Learn

Yes, once I installed the TA_ForIndexers the indexes where all created.

I can create manual notables no problems.  And if I create an alert in Splunk and make the alert action to create a notable, that works.

However, attempting to create a notable based on a correlative search in ES is not working.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...