<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding Additional fields to notable events in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adding-Additional-fields-to-notable-events/m-p/660616#M11746</link>
    <description>&lt;P&gt;Hello, Just checking through if the issue was resolved or you have any further questions?&lt;/P&gt;</description>
    <pubDate>Fri, 13 Oct 2023 06:15:41 GMT</pubDate>
    <dc:creator>meetmshah</dc:creator>
    <dc:date>2023-10-13T06:15:41Z</dc:date>
    <item>
      <title>Adding Additional fields to notable events</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adding-Additional-fields-to-notable-events/m-p/660008#M11732</link>
      <description>&lt;P&gt;I am pretty new to ES correlation seraches and I am trying to figure out how to add additionals fields to notable events to make it esier to investigate. We have this correlation serach enabled "&lt;STRONG&gt;ESCU - Detect New Local Admin account - Rule&lt;/STRONG&gt;"&lt;/P&gt;&lt;P&gt;`wineventlog_security` EventCode=4720 OR (EventCode=4732 Group_Name=Administrators) | transaction member_id connected=false maxspan=180m | rename member_id as user | stats count min(_time) as firstTime max(_time) as lastTime by user dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `detect_new_local_admin_account_filter`&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;When I run the above serach using the search and reporting app I get way more fields than what I see on the&amp;nbsp;&lt;STRONG&gt;Additional Fields&lt;/STRONG&gt; from the notable itself. for example, in the notable event the &lt;STRONG&gt;User&lt;/STRONG&gt; field shows the SID and no other fields to idenity the actual username. To fix this I could add the field&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;Account_Name &lt;/STRONG&gt;that shows when I&amp;nbsp; run the above serach from the search and reporting app.&amp;nbsp; I tried adding that field by going into Configure -&amp;gt; Incident Management -&amp;gt; Incidnet Review Settings -&amp;gt;&amp;nbsp;Incident Review - Event Attributes. But it is still not showing. Am I missing something here?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2023 16:12:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adding-Additional-fields-to-notable-events/m-p/660008#M11732</guid>
      <dc:creator>Albert_Cyber</dc:creator>
      <dc:date>2023-10-06T16:12:46Z</dc:date>
    </item>
    <item>
      <title>Re: Adding Additional fields to notable events</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adding-Additional-fields-to-notable-events/m-p/660089#M11733</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/261218"&gt;@Albert_Cyber&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You have used the right way of&amp;nbsp;&lt;SPAN&gt;Configure -&amp;gt; Incident Management -&amp;gt; Incident Review Settings -&amp;gt;&amp;nbsp;Incident Review - Event Attributes. Just make sure you click the save button at the very bottom (I have seen a customer who had a similar issue and all it needed was to click on the "Save" button at the very end)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the issue is still not resolved, can you please provide below information / screenshots -&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;- Search results showing the field is available&lt;/P&gt;&lt;P&gt;&amp;nbsp;- Notable configuration (AR) screenshot&lt;/P&gt;&lt;P&gt;&amp;nbsp;-&amp;nbsp;Event Attributes screenshot&lt;/P&gt;</description>
      <pubDate>Sun, 08 Oct 2023 05:15:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adding-Additional-fields-to-notable-events/m-p/660089#M11733</guid>
      <dc:creator>meetmshah</dc:creator>
      <dc:date>2023-10-08T05:15:28Z</dc:date>
    </item>
    <item>
      <title>Re: Adding Additional fields to notable events</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adding-Additional-fields-to-notable-events/m-p/660616#M11746</link>
      <description>&lt;P&gt;Hello, Just checking through if the issue was resolved or you have any further questions?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 06:15:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adding-Additional-fields-to-notable-events/m-p/660616#M11746</guid>
      <dc:creator>meetmshah</dc:creator>
      <dc:date>2023-10-13T06:15:41Z</dc:date>
    </item>
    <item>
      <title>Re: Adding Additional fields to notable events</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adding-Additional-fields-to-notable-events/m-p/661069#M11750</link>
      <description>&lt;P&gt;Hi meetmshah thanks for the follow up! I was able to fix this issue by adding this agurment to the search values(field_name)&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 17:25:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adding-Additional-fields-to-notable-events/m-p/661069#M11750</guid>
      <dc:creator>Albert_Cyber</dc:creator>
      <dc:date>2023-10-17T17:25:46Z</dc:date>
    </item>
  </channel>
</rss>

