SecOps forum
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Forum Posts

SIR Playbook Promote to Major Security Incident

Hi All,I'm creating playbooks to deal with Security Incident and Major Security Incident processes. One of my requests is to, based on conditions, trigger buttons either Promote Major Security Incident or Propose Major Security Incident directly from...

artur3 by Mega Guru
  • 449 Views
  • 1 replies
  • 0 helpfuls

Resolved! Vulnerability Assignment Rule Logic and Execution Order

Hi There, Just wanting some clarity around how vulnerability assignment rules are applied when a new VI is created. We currently have a few hundred vulnerability assignment rules configured because each technology type have different requirements for...

Nicole Allen by Kilo Contributor
  • 4234 Views
  • 8 replies
  • 4 helpfuls

Report pulling

Hi,I have to pull a report with records close to 2 million from VIT table with 8 million active records.How to achieve it, I have a brief Idea about the pagination concept, can someone explain in detail about this. Or any other solution which doesn't...

What happens to open detections when a VIT is closed

Hello Everyone,We encountered a situation where a VIT was closed with the reason field as "invalid". The worknotes mention the following:Additional Information: Closed because of CIs do not matchClosed by: SecCommon SystemClosed VIT (VITXXXXXXX) and ...

Splunk Enterprise Event ingestion for Security Operation plugin COST

HI Community!I want to install the Splunk Enterprise Event ingestion for Security Operation plugin, but i want to make sure that this plugin does not have costI saw that I can install in the production instance but...Do you know if this plugin have c...

AB6 by Tera Contributor
  • 435 Views
  • 1 replies
  • 0 helpfuls