Splunk Enterprise Security

What populates the list of "Owners" in the ES App?

vanderaj2
Path Finder

Hey Splunkers,

I'd like to assign an owner to some events appearing in the 'Incident Review" dashboard in the Enterprise Security App.

However, I only see a few users appearing in the "Owner" drop-down list. Some users I'd like to assign the events to as Owners are not in this drop-down list.

Does anyone know what populates the Owners list? Is there some lookup table somewhere? LDAP? Other?

Thanks!

1 Solution

smoir_splunk
Splunk Employee
Splunk Employee

The notable_owners_lookup is populated by the Threat - Notable Owners - Lookup Gen saved search. The list is limited by those that have the capability to own notable events, and if you use SAML authentication with ES, the list can take some time to populate. Check to see if all of the users you expect to see in the list have the capability to own notable events.

View solution in original post

smoir_splunk
Splunk Employee
Splunk Employee

The notable_owners_lookup is populated by the Threat - Notable Owners - Lookup Gen saved search. The list is limited by those that have the capability to own notable events, and if you use SAML authentication with ES, the list can take some time to populate. Check to see if all of the users you expect to see in the list have the capability to own notable events.

vanderaj2
Path Finder

Perfect. That was the answer - thank you! I had to make sure the right users had the capability to own notable events, and I noticed that somebody had disabled the "Threat - Notable Owners - Lookup Gen" saved search. Once I added the correct capability and ran the saved search, the lookup table updated with the other users I was expecting to see.

0 Karma

smoir_splunk
Splunk Employee
Splunk Employee

I'm glad that fixed it! It's also worth noting that most of the lookup gen searches are performing useful internal tasks like this, and when making the effort to reduce the number of searches running overall, it's useful to dig into what the searches are doing before disabling them.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...