<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Findings Comments in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Findings-Comments/m-p/754320#M12720</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our team has recently upgraded to ES 8, we use to have a dashboard that linked notables to closure comments for review.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since the upgrade to ES 8 we have not been able to review notes in bulk in association to a particular finding. The notes are stored within the KV store lookup 'mc_notes', however this table only displays the notes and not the finding it is associated with.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What would be the best way of linking notes with a particular finding, and what would be the SPL for this search.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 14 Oct 2025 22:19:08 GMT</pubDate>
    <dc:creator>jabson</dc:creator>
    <dc:date>2025-10-14T22:19:08Z</dc:date>
    <item>
      <title>Findings Comments</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Findings-Comments/m-p/754320#M12720</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our team has recently upgraded to ES 8, we use to have a dashboard that linked notables to closure comments for review.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since the upgrade to ES 8 we have not been able to review notes in bulk in association to a particular finding. The notes are stored within the KV store lookup 'mc_notes', however this table only displays the notes and not the finding it is associated with.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What would be the best way of linking notes with a particular finding, and what would be the SPL for this search.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Oct 2025 22:19:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Findings-Comments/m-p/754320#M12720</guid>
      <dc:creator>jabson</dc:creator>
      <dc:date>2025-10-14T22:19:08Z</dc:date>
    </item>
    <item>
      <title>Re: Findings Comments</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Findings-Comments/m-p/756361#M12789</link>
      <description>&lt;P&gt;Follow this&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/313602"&gt;@jabson&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunk.my.site.com/customer/s/article/Notable-Comments-are-no-longer-found-in-index-audit-or-in-incident-review" target="_blank"&gt;https://splunk.my.site.com/customer/s/article/Notable-Comments-are-no-longer-found-in-index-audit-or-in-incident-review&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2025 21:04:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Findings-Comments/m-p/756361#M12789</guid>
      <dc:creator>sohailmohammed</dc:creator>
      <dc:date>2025-12-09T21:04:57Z</dc:date>
    </item>
  </channel>
</rss>

