Splunk® Enterprise Security

Use Cases

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Add a risk message and a risk score to a notable

Ram adds a risk message and a risk score to the notable event that represents a threat by creating an adaptive response action. Adaptive response actions can be used to gather more information, take an action in another system, send information to another system, modify a risk score, and so on. Adding a custom risk message helps Ram to build detections based on specific information, such as risk scores, instead of merely relying on the Risk Analysis data model schema.

  1. From a risk notable event, Ram selects the arrow to expand the Actions column and clicks Run Adaptive Response Actions.
  2. Ram clicks Add New Response Action and selects the Risk Analysis adaptive response action from the dropdown list to create risk modifier events in the risk index.
  3. Ram types a risk message, Possible Bypass of User Account Controls.
  4. Ram also adds a risk modifier by populating the following fields:
    • Risk Score
    • Risk Object Field
    • Risk Object Type
  5. Ram clicks Run to run the adaptive risk action on the notable.
Last modified on 19 January, 2022
PREVIOUS
Classify risk objects based on annotations
  NEXT
Adjust risk scores for specific objects

This documentation applies to the following versions of Splunk® Enterprise Security: 7.0.1, 7.0.2


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters