<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to create notable manually with selected timestamp? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-create-notable-manually-with-selected-timestamp/m-p/644984#M11540</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="c"&gt;| stats count 
| eval _time="1685158808"
| eval rule_title="Test notable" 
| eval security_domain="Network"
| eval urgency="Medium"
| eval rule_name="Test rule"
| eval dest="8.8.8.8"
| eval src="1.1.1" 
| eval desc="Please investigate firewall log, and action"
| sendalert notable param.mapfields=_time,desc,rule_id,rule_name,nes_fields,drilldown_name,drilldown_search,governance,control,default_owner,drilldown_earliest_offset,drilldown_latest_offset,next_steps,investigation_profiles,extract_artifacts,recommended_actions&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;BR /&gt;Is it possible to use a timestamp to change the notable creation date time? it is creating notable everytime i hit search with the above query.`&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Additionally how do i move my description from below to the above description?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bluewizard_0-1685419359576.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25603iE39F5EEBB95A6F97/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bluewizard_0-1685419359576.png" alt="bluewizard_0-1685419359576.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 30 May 2023 14:20:32 GMT</pubDate>
    <dc:creator>bluewizard</dc:creator>
    <dc:date>2023-05-30T14:20:32Z</dc:date>
    <item>
      <title>How to create notable manually with selected timestamp?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-create-notable-manually-with-selected-timestamp/m-p/644984#M11540</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="c"&gt;| stats count 
| eval _time="1685158808"
| eval rule_title="Test notable" 
| eval security_domain="Network"
| eval urgency="Medium"
| eval rule_name="Test rule"
| eval dest="8.8.8.8"
| eval src="1.1.1" 
| eval desc="Please investigate firewall log, and action"
| sendalert notable param.mapfields=_time,desc,rule_id,rule_name,nes_fields,drilldown_name,drilldown_search,governance,control,default_owner,drilldown_earliest_offset,drilldown_latest_offset,next_steps,investigation_profiles,extract_artifacts,recommended_actions&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;BR /&gt;Is it possible to use a timestamp to change the notable creation date time? it is creating notable everytime i hit search with the above query.`&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Additionally how do i move my description from below to the above description?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bluewizard_0-1685419359576.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25603iE39F5EEBB95A6F97/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bluewizard_0-1685419359576.png" alt="bluewizard_0-1685419359576.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 14:20:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-create-notable-manually-with-selected-timestamp/m-p/644984#M11540</guid>
      <dc:creator>bluewizard</dc:creator>
      <dc:date>2023-05-30T14:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: Create notable manually with selected timestamp</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-create-notable-manually-with-selected-timestamp/m-p/644988#M11541</link>
      <description>&lt;P&gt;is this technically possible, or everytime i run sendalert notable it will create a notable with time now?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 06:15:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-create-notable-manually-with-selected-timestamp/m-p/644988#M11541</guid>
      <dc:creator>bluewizard</dc:creator>
      <dc:date>2023-05-30T06:15:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to create notable manually with selected timestamp?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-create-notable-manually-with-selected-timestamp/m-p/650933#M11621</link>
      <description>&lt;P&gt;AFAIK, The notable time is the time when the event gets triggered and indexed (and not _time from the events). However, I have heard that there is a feature in the upcoming version of ES where we can select notable time.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 06:38:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-create-notable-manually-with-selected-timestamp/m-p/650933#M11621</guid>
      <dc:creator>meetmshah</dc:creator>
      <dc:date>2023-07-18T06:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to create notable manually with selected timestamp?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-create-notable-manually-with-selected-timestamp/m-p/702560#M12137</link>
      <description>&lt;P&gt;You can use "rule_description" as the field for&lt;SPAN&gt;&amp;nbsp;the above description.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2024 04:02:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-create-notable-manually-with-selected-timestamp/m-p/702560#M12137</guid>
      <dc:creator>johnlee2327</dc:creator>
      <dc:date>2024-10-23T04:02:17Z</dc:date>
    </item>
  </channel>
</rss>

