<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search Notables for Open and Closure Times in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Search-Notables-for-Open-and-Closure-Times/m-p/559862#M10072</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236253"&gt;@splunkeradmin22&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Have a look at the below macro:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|`incident_review`&lt;/LI-CODE&gt;</description>
    <pubDate>Fri, 16 Jul 2021 18:51:19 GMT</pubDate>
    <dc:creator>efika</dc:creator>
    <dc:date>2021-07-16T18:51:19Z</dc:date>
    <item>
      <title>Search Notables for Open and Closure Times</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Search-Notables-for-Open-and-Closure-Times/m-p/558908#M10047</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;I am trying to write a query that will allow me to use my notable_events table, display the time the notable opened and the time it was closed.&lt;/P&gt;&lt;P&gt;Looking through the forums I found:&lt;/P&gt;&lt;P&gt;|eval _time=strftime(_time,"%Y/%m/%d %T")&lt;BR /&gt;|eval review_time=strftime(review_time,"%Y/%m/%d %T")&lt;BR /&gt;|eval assign_time = case(isnotnull(owner), _time) | eval close_time = case(status=5, review_time)&lt;BR /&gt;|stats min(_time) as notable_time min(assign_time) as assign_time min(close_time) as close_time by AlertTitle,owner&lt;/P&gt;&lt;P&gt;&amp;nbsp;But that isn't quite working as it returns 0 results.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 20:25:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Search-Notables-for-Open-and-Closure-Times/m-p/558908#M10047</guid>
      <dc:creator>splunkeradmin22</dc:creator>
      <dc:date>2021-07-09T20:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: Search Notables for Open and Closure Times</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Search-Notables-for-Open-and-Closure-Times/m-p/559862#M10072</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236253"&gt;@splunkeradmin22&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Have a look at the below macro:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|`incident_review`&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 16 Jul 2021 18:51:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Search-Notables-for-Open-and-Closure-Times/m-p/559862#M10072</guid>
      <dc:creator>efika</dc:creator>
      <dc:date>2021-07-16T18:51:19Z</dc:date>
    </item>
  </channel>
</rss>

