Splunk Enterprise

RBA - Use preexisting field for risk object score

Scottk1
Loves-to-Learn Lots

Hello,

We ingest logs from another vendor to Splunk, each event contains a "score" field which is predetermined by the 3rd party ranging from 0 - 100.

Is there away to add that field value to the risk object score instead of a static risk score in the Risk analysis Adaptive response? 

Have been looking at using the Risk factor editor but cant see a way other than setting the static value in the Adaptive response to 100 then creating 100 risk factor like this
if('score'="10",0.1,1)
if('score'="11",0.11,1)
if('score'="12",0.12,1) so on and so on.

Thanks 

 

 

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...