Use the script editor to format alert values for the Splunk Enterprise Security Event Ingestion integration
In addition to the directly mapped fields from the ingested notable event values, and the values you enter manually, use the script editor to format field values on the security incident during the mapping step.
시작하기 전에
Role required: sn_si.ingestion_profile_admin
주:
Users with the sn_si.admin role can perform all operations available to a profile admin, as the sn_si.admin role inherits the required permissions by default.
이 태스크 정보
In certain cases, Splunk Enterprise Security notable event values are mapped to the Category, Configuration item (CI), and Observable fields on the SIR incident are not supported. You might prefer to edit the mapped values. If you want to translate the value of a Splunk Enterprise Security notable event to a value that is supported by these fields on the SIR security incident, use the script editor.