Splunk Enterprise Security

Enterprise Security Suite Incident Review - How do you edit the owners list?

vaudajordan
Engager

How do you control who is in the drop down list of owners, so you can assign a ticket to someone else? It seems to have picked a bunch of random people and not the two people I need in there.

Labels (1)
1 Solution

LukeMurphey
Champion

Make sure that the users you want to assign notable events to have the "can_own_notable_events" capability. Once you add that, you should see them in the list of people you can assign notable events to in a few minutes.

View solution in original post

lmyrefelt
Builder

I belive your users need to be member of the "Security Analyst" (dont remmember the "correct" name) role

Read the docs, it is described in there how to setup / configure it correctly. 😉

0 Karma

LukeMurphey
Champion

Make sure that the users you want to assign notable events to have the "can_own_notable_events" capability. Once you add that, you should see them in the list of people you can assign notable events to in a few minutes.

aakwah
Builder

The problem with this solution is that all Admins have the capability "can_own_notable_events" and they appear in the list among SOC analysts.

The woraround I found is to disable "es_notable_events" in Lookup definitions page, and edit the kv-store lookup "notable_owners" by the app "Splunk App for Lookup File Editing".

The impact of this solution is that newly added SOC members need to be added manually to the "notable_owners" lookup.

 

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...