Hello, I have followed https://docs.splunk.com/Documentation/ES/6.6.2/Admin/Customizenotables and created Additional Fields under "Incident Review Settings" page and saved my changes.&n...
...ast 60 minutes, and the notable has some variables.
The inspector shows that it is not able to find events (considering the search runs fine in flashtimeline). I know it is a bit ambiguous, but i...
I've written some Correlation Searches inEnterpriseSecurity and saved them in a custom app: "SA-Custom". I've chosen Notableevent as the adaptive response and filled in some amount of detail: T...
...ssigned to someone. It appears as though the only way to customizenotableeventinformation like this is with a correlation search.
Is there a way to use a simple search, such as above, as a c...
...eview settings.
Sorry this is rather vague - Just looking to find ways to customize these settings on the basis of different notableevents.
Thanks,
Adam.
I'm a Splunk administrator, not a Windows administrator, so my Windows knowledge is limited. Nonetheless, many teams can benefit from having Windows Event Log data inSplunk. What are the best p...
...EnterpriseSecuritySuite) from etc/shcluster/apps to etc/apps folder Ran the upgrade command – (/opt/splunk/bin/splunkinstall app ./splunk-enterprise-security_620.spl -update 1) Ran the essinstall command as per the in...
Hi there,
Just noticed that the NotableEvent Suppressions page inSplunkEnterpriseSecurity (Configure --> Incident Management --> NotableEvent Suppressions) is only showing 30 out of o...