Splunk Enterprise

RBA - Use preexisting field for risk object score

Scottk1
Loves-to-Learn Lots

Hello,

We ingest logs from another vendor to Splunk, each event contains a "score" field which is predetermined by the 3rd party ranging from 0 - 100.

Is there away to add that field value to the risk object score instead of a static risk score in the Risk analysis Adaptive response? 

Have been looking at using the Risk factor editor but cant see a way other than setting the static value in the Adaptive response to 100 then creating 100 risk factor like this
if('score'="10",0.1,1)
if('score'="11",0.11,1)
if('score'="12",0.12,1) so on and so on.

Thanks 

 

 

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...