All Apps and Add-ons

Unable to set the "action.threat_activity" to "1" from the advanced edit option of the saved search

renjujacob88
Path Finder

Hi Splunkers,

I just created a saved search and my agenda is to write the event to threat_activity index.

To do this i need to enable "action.threat_activity" param to 1. But when i change the parameter to 1 and save it its not updating instead its showing as action.threat_activity=0.

Is there a work around on this issue. The only thing i need is to write the saved search result to threat_activity.

Kindly help

alt text

0 Karma
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...