Splunk Enterprise Security

splunk Enterprise security

vikram1583
Explorer

I created few correlation searches notable events in Enterprise security and in Incident Review - Table Attributes I added src_user , src_ip, src_dest I am not able to see results there can come one help me in fixing this?

0 Karma

lakshman239
SplunkTrust
SplunkTrust

You need to make sure your correlation search is producing required results. The results should have values in the fields src_user, src_ip etc.. If so, you can see the actual values for the notable in Incident review page

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...