...lert_actions.conf is causing the AdaptiveResponseActions menu to malfunction on our Splunk ES search-head.
To recreate: Open EnterpriseSecurity -> Configure -> Content Management -> Select aCorrelation...
I have installed EnterpriseSecurityApp. I review Security Domain, in particular, Access and Network sections and I see many events coming from my AD, Office 365, and Firewalls. However,&n...
...stalling correctly and are visible in the Alert actions view, not all the actionsare visible in the EnterpriseSecurity drop-down list (While creating acorrelationsearch), only a certain number of actions...
From aSplunk custom App, I need to add the workflow action which should be displayed under the Actions menu for the notable event in the Incident Review view in the SplunkEnterpriseSecurity. I h...
Hi,
How can I configureaCorrelationSearchin ES to add risk to 2 objects (src & dest)? I can only configureaAdaptiveResponseAction once from the drop down menu.
Savedsearches.conf s...