SecOps forum
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Forum Posts

Report pulling

Hi,I have to pull a report with records close to 2 million from VIT table with 8 million active records.How to achieve it, I have a brief Idea about the pagination concept, can someone explain in detail about this. Or any other solution which doesn't...

What happens to open detections when a VIT is closed

Hello Everyone,We encountered a situation where a VIT was closed with the reason field as "invalid". The worknotes mention the following:Additional Information: Closed because of CIs do not matchClosed by: SecCommon SystemClosed VIT (VITXXXXXXX) and ...

Splunk Enterprise Event ingestion for Security Operation plugin COST

HI Community!I want to install the Splunk Enterprise Event ingestion for Security Operation plugin, but i want to make sure that this plugin does not have costI saw that I can install in the production instance but...Do you know if this plugin have c...

AB6 by Tera Contributor
  • 474 Views
  • 1 replies
  • 0 helpfuls

Resolved! Security Incident Response Worksapce

Hi,I hope you can help me. I would like to configure the Security Incident Response Workspace, but I don't know where to start. Could you help me with info, more technical, not process and interface.Thanks!  

AndreeaI by Tera Contributor
  • 716 Views
  • 2 replies
  • 1 helpfuls

Reapply All Remediation Target Rules

We recently recreated our remediation target rules and have been rolling them out in phases to UAT. There are some VIT's that are not being assigned a remediation target rule, despite there being a VIT that meets the conditions of the remediation tar...

14Hernan by Tera Contributor
  • 669 Views
  • 1 replies
  • 0 helpfuls

How to link Discovered Items and CI

Hello everyone.The data integrated by the SecOps function initially searches the CMDB using lookup rules and identification rules.If there is no CI as a result of the search, a record such as Unclass Hardware is created.This created record is linked ...

kuroiwa by Tera Contributor
  • 641 Views
  • 2 replies
  • 0 helpfuls

False positive workflow in vulnerability Response

I would like to understand how the application behaves during the subsequent month’s scan if the same vulnerability reappears after an FP (False Positive) request has been raised and closed.Currently, we are marking the FP status only in ServiceNow, ...