- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-24-2024 08:01 AM - edited 07-24-2024 08:02 AM
Hey @dhruv_gupta - looks like @Martin Dewit has got you on the right track.
A few questions that may help:
1) Have we already configured MITRE ATT&CK - and pulled in the data from the "TAXII Profiles"?
- Assuming we went with "Enterprise ATT&CK" but can you confirm?
2) What flavor of Splunk are we using?
- Are we using Splunk Enterprise Security (ES) - where the Notable Events actually have MITRE ATT&CK TTPs in the Notable event field data?
3) How are we integration Splunk with SecOps?
- Are we using the NOW Store App - and setup the Profiles for Automated ingestion (scheduled)?
- Or, are we first testing with the "Manual" option to push Notables to NOW with the button?
4) Can you confirm on the ServiceNow config side -> the Extraction Rule for Splunk -> has the Ignore option disabled (false)?