<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Additional field - event acknowledgment in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Additional-field-event-acknowledgment/m-p/13615#M65</link>
    <description>&lt;P&gt;Yes, we need this!!!&lt;/P&gt;</description>
    <pubDate>Fri, 24 Sep 2010 07:02:28 GMT</pubDate>
    <dc:creator>araitz</dc:creator>
    <dc:date>2010-09-24T07:02:28Z</dc:date>
    <item>
      <title>Additional field - event acknowledgment</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Additional-field-event-acknowledgment/m-p/13612#M62</link>
      <description>&lt;P&gt;Is there a way to add an additional field to every event for acknowledgment?&lt;/P&gt;

&lt;P&gt;I'm analyzing failed login attempts. As some of them happened for a known reason I'd like to mark them somehow in the final report.&lt;/P&gt;</description>
      <pubDate>Mon, 17 May 2010 09:33:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Additional-field-event-acknowledgment/m-p/13612#M62</guid>
      <dc:creator>kkuminsky</dc:creator>
      <dc:date>2010-05-17T09:33:23Z</dc:date>
    </item>
    <item>
      <title>Re: Additional field - event acknowledgment</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Additional-field-event-acknowledgment/m-p/13613#M63</link>
      <description>&lt;P&gt;This sure would be a nice feature.&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2010 19:41:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Additional-field-event-acknowledgment/m-p/13613#M63</guid>
      <dc:creator>netwrkr</dc:creator>
      <dc:date>2010-05-19T19:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: Additional field - event acknowledgment</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Additional-field-event-acknowledgment/m-p/13614#M64</link>
      <description>&lt;P&gt;I am doing something similar to what you're trying to do -- basically I am tagging events in splunk with change ticket numbers using lookups. You should be able to tune this to your requirements:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/questions/3982/correlate-and-tag-splunk-events-with-change-control-tickets" rel="nofollow"&gt;http://answers.splunk.com/questions/3982/correlate-and-tag-splunk-events-with-change-control-tickets&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2010 02:20:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Additional-field-event-acknowledgment/m-p/13614#M64</guid>
      <dc:creator>ftk</dc:creator>
      <dc:date>2010-07-02T02:20:14Z</dc:date>
    </item>
    <item>
      <title>Re: Additional field - event acknowledgment</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Additional-field-event-acknowledgment/m-p/13615#M65</link>
      <description>&lt;P&gt;Yes, we need this!!!&lt;/P&gt;</description>
      <pubDate>Fri, 24 Sep 2010 07:02:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Additional-field-event-acknowledgment/m-p/13615#M65</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2010-09-24T07:02:28Z</dc:date>
    </item>
  </channel>
</rss>

