How do I forward Splunk Mission Control Investigations to SIR?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
39m ago
Our SOC is using the Splunk SIEM known as Mission Control. All of their investigations into notable events are handled through the Splunk SIEM. However, we need to have the data sent to SIR so we can provide reports and metrics of their investigations. It needs to be bidirectional, because they will manually want to push an investigation to SIR, and updates to the investigation in Splunk will need to be sync'd up with the SIR ticket until it is Closed.
Looking at the Splunk ES Integration for SecOps looks like it only works with events linking to SIR tickets, not an investigation. I asked AI how to do it, and of course doesn't mean it's right, but it says I need to use the Splunk Enterprise DATA Integration for Security Operations and the Splunk Search Integration for Security Operations. I don't see a Splunk DATA Integration in the ServiceNow store.
Has anyone been able to set this up, or does anyone know how I need to set it up? BTW we are on the version Australia.
Thank you,
Cheryl
