Splunk SOAR

Entity Risk Reduction upon False Positive disposition

pruthviraj_k_m
Explorer

Hi All,

I am trying to build a playbook that reduces the risk of an entity in any of the splunk notable only when the notable disposition is set to False Positive by the analyst. I need to negate the same amount of risk added by the finding score as well as intermediate finding score. Is it possible to do so? What is the process for that?

I did find an approach to post the risk event but not able to create any event. Additionally, I want to know how to calculate the amount of risk to be negated?

Thanks!

Labels (1)
0 Karma

phanTom
SplunkTrust
SplunkTrust

@pruthviraj_k_m I think I managed to find the docs around what actions are available on the ES Connector in SOAR and I can't see a direct "Risk Modifier" action. 

There is an API for ES Risk where you can update risk but I can't see if that's an action already available or whether you may need to build the capability into SOAR. 

My methodology for what you are trying to achieve:

1. Upon container close run a playbook to check for disposition
2. If "false positive" identify the risk object (asset/identity)
3. Run search in the risk index to ascertain the score that was added
4. Calculate the score and pass the - value (e.g. -40) into the reduction action, along with the relevant entity
5. Check for success


-- Hope this helps, if so consider leaving some Karma. Even better is if this fixed your issue, that you mark as a solution for others to find. Happy SOARing!! ---
0 Karma

phanTom
SplunkTrust
SplunkTrust

@pruthviraj_k_m you are on the right track with the risk event to reduce the risk score AFAIK. There should be an event in the risk index that shows the entity it's assigned to and the amount of risk applied. You will need to run a search from SOAR to find the risk addition using the information in the container and then perform the relevant risk reduce after. 


You may also need to be aware if a risk modifier was provided to the score, but if the total score added is all you want to then remove, I think you are good with this approach. 

-- Hope this helps, if so consider leaving some Karma. Even better is if this fixed your issue, that you mark as a solution for others to find. Happy SOARing!! ---
0 Karma

pruthviraj_k_m
Explorer

Thanks @phanTom .

I want to know, if we can use ES's risk modifier action in our playbook to reduce the overall risk score of an entity? If so, should we just negate whatever the finding score that we have received in the splunk notable or there exists any calculation to find out how much risk should be reduced?

 

0 Karma

phanTom
SplunkTrust
SplunkTrust

@pruthviraj_k_m unfortunately I don't have a SOAR instance attached to an ES instance and I can't see a way to get the ES App onto my current SOAR Sandbox. 

However, if there is an action to reduce risk on an entity by a value then all you should need to do is find the score assigned at the time of the alert (or could be multiple intermediate findings) so I would recommend running a search for all Risk events for the entity in the risk index, then you should be able to understand the value that was added, then pass that into the risk modification action. 

-- Hope this helps, if so consider leaving some Karma. Even better is if this fixed your issue, that you mark as a solution for others to find. Happy SOARing!! ---
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...