<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Enterprise Security 8.0 in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-8-0/m-p/711559#M12348</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/265274"&gt;@Fara7at08&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The "Short ID" button might be missing due to changes in the interface or settings during the upgrade.&amp;nbsp;According to the&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/ES/8.0.2/Install/UpgradetoNewVersion" target="_blank" rel="noopener"&gt;Upgrade Splunk Enterprise Security - Splunk Documentation&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;H3&gt;&lt;SPAN class=""&gt;After upgrading to version 7.0.0&lt;/SPAN&gt;&lt;/H3&gt;&lt;P&gt;When you upgrade the Splunk Enterprise Security app to versions 7.0.0 or higher, the short IDs for notables that were created prior to the upgrade are not displayed on the Incident Review page. As a workaround, you can recreate all the short IDs that were available prior to the upgrade.&lt;/P&gt;</description>
    <pubDate>Fri, 14 Feb 2025 05:23:31 GMT</pubDate>
    <dc:creator>kiran_panchavat</dc:creator>
    <dc:date>2025-02-14T05:23:31Z</dc:date>
    <item>
      <title>Splunk Enterprise Security 8.0</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-8-0/m-p/711516#M12344</link>
      <description>&lt;P&gt;&lt;SPAN&gt;when i upgrade ES to 8.0.2 i missed the "Short ID " button in the Additional Field, also i can't search about the case id instead of time&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2025 18:09:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-8-0/m-p/711516#M12344</guid>
      <dc:creator>Fara7at08</dc:creator>
      <dc:date>2025-02-13T18:09:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security 8.0</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-8-0/m-p/711559#M12348</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/265274"&gt;@Fara7at08&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The "Short ID" button might be missing due to changes in the interface or settings during the upgrade.&amp;nbsp;According to the&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/ES/8.0.2/Install/UpgradetoNewVersion" target="_blank" rel="noopener"&gt;Upgrade Splunk Enterprise Security - Splunk Documentation&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;H3&gt;&lt;SPAN class=""&gt;After upgrading to version 7.0.0&lt;/SPAN&gt;&lt;/H3&gt;&lt;P&gt;When you upgrade the Splunk Enterprise Security app to versions 7.0.0 or higher, the short IDs for notables that were created prior to the upgrade are not displayed on the Incident Review page. As a workaround, you can recreate all the short IDs that were available prior to the upgrade.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2025 05:23:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-8-0/m-p/711559#M12348</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-02-14T05:23:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security 8.0</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-8-0/m-p/711589#M12350</link>
      <description>&lt;P&gt;Thank you for your reply, i found the solution, it's supported you find follow the below approach.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;You need to click on a finding to open the right-hand side panel, then click the 3 dots next to "start an investigation" and select "share a finding". This will generate the shortID and share link. I've attached a screenshot.&lt;DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Fara7at08_1-1739533448590.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/34504i65B372ED50115B3C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Fara7at08_1-1739533448590.png" alt="Fara7at08_1-1739533448590.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 14 Feb 2025 11:45:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-8-0/m-p/711589#M12350</guid>
      <dc:creator>Fara7at08</dc:creator>
      <dc:date>2025-02-14T11:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security 8.0</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-8-0/m-p/711590#M12351</link>
      <description>&lt;P&gt;On top of what&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/264857"&gt;@kiran_panchavat&lt;/a&gt;&amp;nbsp;mentioned, once we generate the Short IDs, we can also add in Incident Review Dashboard as a custom field -&amp;nbsp;&lt;A href="https://www.splunk.com/en_us/blog/security/modifying-the-incident-review-page.html#:~:text=To%20configure%20Incident%20Review%20and,see%20Incident%20Review%20%E2%80%93%20Event%20Attributes" target="_blank"&gt;https://www.splunk.com/en_us/blog/security/modifying-the-incident-review-page.html#:~:text=To%20configure%20Incident%20Review%20and,see%20Incident%20Review%20%E2%80%93%20Event%20Attributes&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2025 11:47:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-8-0/m-p/711590#M12351</guid>
      <dc:creator>meetmshah</dc:creator>
      <dc:date>2025-02-14T11:47:43Z</dc:date>
    </item>
  </channel>
</rss>

