kyberis:threat_activity. It is available on every core Splunk alert, and — via
its Common Action Model metadata — as an adaptive response action in Enterprise
Security, verified on ES 8.
It reuses the same enrichment core and KV Store cache as | kyberis, so
alert-triggered enrichments and interactive searches warm each other’s cache.
Parameters
Configured per alert, with defaults fromdefault/alert_actions.conf:
The role that owns the alert needs
list_storage_passwords and write access to
the destination index; see Permissions.
Indexed event shape
One event per unique indicator. A value seen in several fields or rows keeps its first occurrence.orig_sid,orig_rid, andsearch_namelink the event back to the triggering search and result row — the linkage Enterprise Security incident review correlates on.- The full
kyberis_*field set is the same as the| kyberisoutput. - The CIM
threat_*fields appear only when the verdict meetscim_min_threat, exactly as at search time. - Events have no embedded timestamp; the index time is the enrichment time
(
DATETIME_CONFIG = CURRENT).
threat_match_value=*, so only events that qualified as
threat matches are tagged threat and enter the Enterprise Security Threat
Intelligence data model. Benign verdicts stay searchable via
sourcetype=kyberis:threat_activity but out of the data model.
Failure policy
The action is designed to degrade rather than lose work:- A mid-run plan limit (HTTP 402) is not a failure. Already-enriched
indicators are indexed with their verdicts, the remainder are indexed with
kyberis_status=plan_limit, a warning is logged, and the action exits 0. - A transport failure annotates affected indicators with
kyberis_status=transport_error— indexed, and retried by later runs since they are never cached — and logs a warning. - Configuration, credential, or missing-index problems exit non-zero with an actionable message and index nothing.
Action output lands in
splunkd.log, component sendmodalert; see
Troubleshooting.
Adaptive response in Enterprise Security
In Enterprise Security, the action appears under adaptive response actions, in the Information Gathering category, through the standard alert-action and Common Action Model mechanism. See the compatibility matrix. Attach it to a detection’s response actions, or run it at triage time from a finding. On ES 8 that is Mission Control: open the finding, then ⋯ → Run adaptive response actions. For the enriched events to reach theThreat_Activity dataset they must be
indexed in threat_activity, which is what the action does by default on an ES
instance. Pointing the action at another index keeps the enrichment but takes
the events out of the data model.
Test an alert action configuration
Trigger it inline withsendalert on any search results:
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=66da6f97e851defcb12af05b800a8a27)
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=37df025ce7a3cc54dd90f8edad1cf54f)