Splunk Enterprise Security

Risk isn't showing up in the Edit Correlation Search?

spctravis
Explorer

I have an app with my alerts. I have risk enabled and it's working however risk isn't showing up in the Edit Correlation Search menu. Is there a setting in a .conf file I am missing? I looked into alert_actions.conf but don't see any other rule with that linking to it. Below is my risk setting for one of my rules:

action.risk = 1
action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 14}]
action.risk.param._risk_message = Wsmprovhost.exe spawned a LOLBAS process on $dest$.
action.risk.param._risk_score = 0
action.risk.param.verbose = 0

Labels (1)
0 Karma

hettervik
Builder

Do you want a correlation search to add risk score to an object? If so, you have to edit the correlation search in Splunk ES, and then add a "Risk Analysis" response action, all the way at the bottom of the edit page. There you can add risk scores to users and systems from you correlation search.

0 Karma

spctravis
Explorer

I want to be able to add the risk using .conf files not go through the gui. 800 plus rules is too many to one by one. 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...