Add ESCU annotations to correlation searches and analytics stories
Add and edit annotations from Enterprise Security Content Update (ESCU) to correlation searches and analytic stories in the use case library of Splunk Enterprise Security to enrich your security content.
Add annotations to a correlation search
Add annotations such as Analytic Story, Confidence, Context, and Impact from Splunk ESCU to your correlation searches for enriching your security content.
Managed annotations are annotations that Splunk ES and ESCU ship by default. Unmanaged annotations are custom annotations that you can add for your specific use case. Annotations are often based on a recognized industry framework such MITRE ATT&CK or KILL CHAIN.
Follow these steps to add annotations to a correlation search:
- From the Content Management page, locate the correlation search you want to edit.
- Click the name of a correlation search on the Content Management page to edit it.
- Scroll to the section on Annotations and add values for managed annotation such as Confidence, Impact, Analytic Story, and Context.
Following annotation types are supported by the correlation search editor:
ESCU annotation type | Description | Example value | Managed/Unmanaged |
---|---|---|---|
Confidence | Numerical value to score confidence level | 50 | Managed |
Impact | Numerical value to score impact | 40 | Managed |
Analytic story | Identifies the analytic story to which the correlation search is linked in the use case library | Ransomware AWS IAM Privilege Escalation |
Unmanaged |
Context | Context for the correlation search?? | Source Cloud Data Scope External |
Unmanaged |
View annotations in analytic stories from the use case library
View annotations that you added to the searches in the Analytic Story details page of the use case library.
- From the Splunk ES menu bar, select Configure > Content > Use Case Library.
- From the use cases filters on the left, click Cloud Security.
- From an Analytic Story, such as AWS Cross Account Activity, click the greater than ( >) symbol to expand the display.
- Scroll to Framework Mapping to view the annotation types supported by the Use Case Library.
- Click the name of the Analytic Story. For example, click AWS Cross Account Activity.
The Analytic Story Details page opens for the story. - Scroll to Cyber Security Framework Attributes to see the various ESCU annotation types associated with the analytic story.
See also
Use security framework annotations in correlation searches
Edit a correlation search
Manage Analytic Stories through the use case library in Splunk Enterprise Security | Configure general settings for Splunk Enterprise Security |
This documentation applies to the following versions of Splunk® Enterprise Security: 7.1.0, 7.1.1, 7.1.2, 7.2.0, 7.3.0, 7.3.1, 7.3.2
Feedback submitted, thanks!