<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Mitre Technique Extraction - Splunk, MISP Nothing working in SecOps forum</title>
    <link>https://www.servicenow.com/community/secops-forum/mitre-technique-extraction-splunk-misp-nothing-working/m-p/2998578#M11758</link>
    <description>&lt;P&gt;Hi all,&lt;BR /&gt;&lt;BR /&gt;We are implementing MITRE framework. We tried configuring auto extraction rule but they dont seem to be working. Has anybody implemented that or can share some insights. That will be really helpful&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://www.servicenow.com/community/user/viewprofilepage/user-id/19160"&gt;@andy_ojha&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 24 Jul 2024 14:26:00 GMT</pubDate>
    <dc:creator>dhruv_gupta</dc:creator>
    <dc:date>2024-07-24T14:26:00Z</dc:date>
    <item>
      <title>Mitre Technique Extraction - Splunk, MISP Nothing working</title>
      <link>https://www.servicenow.com/community/secops-forum/mitre-technique-extraction-splunk-misp-nothing-working/m-p/2998578#M11758</link>
      <description>&lt;P&gt;Hi all,&lt;BR /&gt;&lt;BR /&gt;We are implementing MITRE framework. We tried configuring auto extraction rule but they dont seem to be working. Has anybody implemented that or can share some insights. That will be really helpful&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://www.servicenow.com/community/user/viewprofilepage/user-id/19160"&gt;@andy_ojha&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 14:26:00 GMT</pubDate>
      <guid>https://www.servicenow.com/community/secops-forum/mitre-technique-extraction-splunk-misp-nothing-working/m-p/2998578#M11758</guid>
      <dc:creator>dhruv_gupta</dc:creator>
      <dc:date>2024-07-24T14:26:00Z</dc:date>
    </item>
    <item>
      <title>Re: Mitre Technique Extraction - Splunk, MISP Nothing working</title>
      <link>https://www.servicenow.com/community/secops-forum/mitre-technique-extraction-splunk-misp-nothing-working/m-p/2998594#M11759</link>
      <description>&lt;P&gt;For Splunk, have you looked at this post?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.servicenow.com/community/secops-forum/configure-splunk-events-to-include-mitre-att-ck-ttps/m-p/1285212" target="_blank" rel="noopener"&gt;https://www.servicenow.com/community/secops-forum/configure-splunk-events-to-include-mitre-att-ck-ttps/m-p/1285212&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For MISP, the docs specify settings within the integration. Have you configured those?&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.servicenow.com/csh?topicname=review-the-misp-integration-settings.html&amp;amp;version=latest" target="_blank"&gt;https://docs.servicenow.com/csh?topicname=review-the-misp-integration-settings.html&amp;amp;version=latest&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 14:44:24 GMT</pubDate>
      <guid>https://www.servicenow.com/community/secops-forum/mitre-technique-extraction-splunk-misp-nothing-working/m-p/2998594#M11759</guid>
      <dc:creator>Martin Dewit</dc:creator>
      <dc:date>2024-07-24T14:44:24Z</dc:date>
    </item>
    <item>
      <title>Re: Mitre Technique Extraction - Splunk, MISP Nothing working</title>
      <link>https://www.servicenow.com/community/secops-forum/mitre-technique-extraction-splunk-misp-nothing-working/m-p/2998598#M11760</link>
      <description>&lt;P&gt;yaa all checked.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 14:48:00 GMT</pubDate>
      <guid>https://www.servicenow.com/community/secops-forum/mitre-technique-extraction-splunk-misp-nothing-working/m-p/2998598#M11760</guid>
      <dc:creator>dhruv_gupta</dc:creator>
      <dc:date>2024-07-24T14:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: Mitre Technique Extraction - Splunk, MISP Nothing working</title>
      <link>https://www.servicenow.com/community/secops-forum/mitre-technique-extraction-splunk-misp-nothing-working/m-p/2998610#M11761</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://www.servicenow.com/community/user/viewprofilepage/user-id/672422"&gt;@dhruv_gupta&lt;/a&gt;&amp;nbsp; - looks like &lt;a href="https://www.servicenow.com/community/user/viewprofilepage/user-id/433745"&gt;@Martin Dewit&lt;/a&gt;&amp;nbsp; has got you on the right track.&lt;BR /&gt;&lt;BR /&gt;A few questions that may help:&lt;BR /&gt;&lt;BR /&gt;1) Have we already configured MITRE ATT&amp;amp;CK - and pulled in the data from the "TAXII Profiles"?&lt;BR /&gt;&amp;nbsp; - Assuming we went with "Enterprise ATT&amp;amp;CK" but can you confirm?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="andy_ojha_0-1721832963928.png"&gt;&lt;img src="https://www.servicenow.com/community/image/serverpage/image-id/374205iAC0AAFEBB85CDEEF/image-size/medium?v=v2&amp;amp;px=400" alt="andy_ojha_0-1721832963928.png" title="andy_ojha_0-1721832963928.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;2) What flavor of Splunk are we using?&lt;BR /&gt;&amp;nbsp; - Are we using Splunk Enterprise Security (ES) - where the Notable Events actually have MITRE ATT&amp;amp;CK TTPs in the Notable event field data?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3) How are we integration Splunk with SecOps?&lt;BR /&gt;&amp;nbsp;- Are we using the NOW Store App - and setup the Profiles for Automated ingestion (scheduled)?&lt;BR /&gt;&amp;nbsp;- Or, are we first testing with the "Manual" option to push Notables to NOW with the button?&lt;BR /&gt;&lt;BR /&gt;4) Can you confirm on the ServiceNow config side -&amp;gt; the Extraction Rule for Splunk -&amp;gt; has the Ignore option disabled (false)?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="andy_ojha_0-1721833336244.png"&gt;&lt;img src="https://www.servicenow.com/community/image/serverpage/image-id/374206i5EA139A81C265880/image-size/medium?v=v2&amp;amp;px=400" alt="andy_ojha_0-1721833336244.png" title="andy_ojha_0-1721833336244.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 15:02:24 GMT</pubDate>
      <guid>https://www.servicenow.com/community/secops-forum/mitre-technique-extraction-splunk-misp-nothing-working/m-p/2998610#M11761</guid>
      <dc:creator>andy_ojha</dc:creator>
      <dc:date>2024-07-24T15:02:24Z</dc:date>
    </item>
    <item>
      <title>Re: Mitre Technique Extraction - Splunk, MISP Nothing working</title>
      <link>https://www.servicenow.com/community/secops-forum/mitre-technique-extraction-splunk-misp-nothing-working/m-p/2998623#M11762</link>
      <description>&lt;P&gt;1;)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dhruv_gupta_0-1721833507161.png"&gt;&lt;img src="https://www.servicenow.com/community/image/serverpage/image-id/374207iDD13618443600601/image-size/medium?v=v2&amp;amp;px=400" alt="dhruv_gupta_0-1721833507161.png" title="dhruv_gupta_0-1721833507161.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;2:) &amp;amp; 3:)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dhruv_gupta_1-1721833570578.png"&gt;&lt;img src="https://www.servicenow.com/community/image/serverpage/image-id/374209iC1A83FF26A686866/image-size/medium?v=v2&amp;amp;px=400" alt="dhruv_gupta_1-1721833570578.png" title="dhruv_gupta_1-1721833570578.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;4:)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dhruv_gupta_2-1721833662954.png"&gt;&lt;img src="https://www.servicenow.com/community/image/serverpage/image-id/374210i4C6F1E3B75DE9F1B/image-size/medium?v=v2&amp;amp;px=400" alt="dhruv_gupta_2-1721833662954.png" title="dhruv_gupta_2-1721833662954.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 09:41:54 GMT</pubDate>
      <guid>https://www.servicenow.com/community/secops-forum/mitre-technique-extraction-splunk-misp-nothing-working/m-p/2998623#M11762</guid>
      <dc:creator>dhruv_gupta</dc:creator>
      <dc:date>2024-07-30T09:41:54Z</dc:date>
    </item>
    <item>
      <title>Re: Mitre Technique Extraction - Splunk, MISP Nothing working</title>
      <link>https://www.servicenow.com/community/secops-forum/mitre-technique-extraction-splunk-misp-nothing-working/m-p/2998692#M11763</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://www.servicenow.com/community/user/viewprofilepage/user-id/672422"&gt;@dhruv_gupta&lt;/a&gt;&amp;nbsp;- that certainly checks all pre-req boxes...&lt;BR /&gt;&lt;BR /&gt;On the Target SIR records being created here -- do any of them have data in any of the MITRE fields at all (i.e. is it partially working - or just not working at all) - see screenshot below.&lt;BR /&gt;&lt;BR /&gt;Can we confirm the MITRE (Attack Patterns) table has data on it -&amp;gt; `sn_ti_stix2_attack_pattern`?&lt;BR /&gt;&lt;BR /&gt;------------------------------------------------------------------------------------&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I think the next best step here would be a NOW Support Case to get eyes on this - especially if we are mostly aligned to baseline configs and no customizations to any of the baseline Script Includes involved.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="andy_ojha_0-1721836323767.png"&gt;&lt;img src="https://www.servicenow.com/community/image/serverpage/image-id/374225iF167629A6E2BDE7D/image-size/medium?v=v2&amp;amp;px=400" alt="andy_ojha_0-1721836323767.png" title="andy_ojha_0-1721836323767.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 15:55:20 GMT</pubDate>
      <guid>https://www.servicenow.com/community/secops-forum/mitre-technique-extraction-splunk-misp-nothing-working/m-p/2998692#M11763</guid>
      <dc:creator>andy_ojha</dc:creator>
      <dc:date>2024-07-24T15:55:20Z</dc:date>
    </item>
    <item>
      <title>Re: Mitre Technique Extraction - Splunk, MISP Nothing working</title>
      <link>https://www.servicenow.com/community/secops-forum/mitre-technique-extraction-splunk-misp-nothing-working/m-p/2998694#M11764</link>
      <description>&lt;P&gt;No data i just created a case&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 15:53:58 GMT</pubDate>
      <guid>https://www.servicenow.com/community/secops-forum/mitre-technique-extraction-splunk-misp-nothing-working/m-p/2998694#M11764</guid>
      <dc:creator>Dhruvii</dc:creator>
      <dc:date>2024-07-24T15:53:58Z</dc:date>
    </item>
  </channel>
</rss>

