<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is it possible to generate a &amp;quot;ticket number&amp;quot; style reference for a notable event? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Is-it-possible-to-generate-a-quot-ticket-number-quot-style/m-p/249657#M1782</link>
    <description>&lt;P&gt;I'd like each notable event that is raised in ES to have a unique "ticket number" style reference, automatically incrementing as events are raised - along the same kind of lines as ticket reference numbers that are created in systems like ServiceNow when a ticket is raised.&lt;/P&gt;

&lt;P&gt;I appreciate that the event_id field is a unique reference for each notable but it's not user friendly enough to be used as a point of reference between multiple analysts&lt;/P&gt;

&lt;P&gt;Is there a way to achieve what I am looking for?&lt;/P&gt;</description>
    <pubDate>Mon, 10 Oct 2016 13:47:32 GMT</pubDate>
    <dc:creator>gmrtn14</dc:creator>
    <dc:date>2016-10-10T13:47:32Z</dc:date>
    <item>
      <title>Is it possible to generate a "ticket number" style reference for a notable event?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Is-it-possible-to-generate-a-quot-ticket-number-quot-style/m-p/249657#M1782</link>
      <description>&lt;P&gt;I'd like each notable event that is raised in ES to have a unique "ticket number" style reference, automatically incrementing as events are raised - along the same kind of lines as ticket reference numbers that are created in systems like ServiceNow when a ticket is raised.&lt;/P&gt;

&lt;P&gt;I appreciate that the event_id field is a unique reference for each notable but it's not user friendly enough to be used as a point of reference between multiple analysts&lt;/P&gt;

&lt;P&gt;Is there a way to achieve what I am looking for?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2016 13:47:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Is-it-possible-to-generate-a-quot-ticket-number-quot-style/m-p/249657#M1782</guid>
      <dc:creator>gmrtn14</dc:creator>
      <dc:date>2016-10-10T13:47:32Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to generate a "ticket number" style reference for a notable event?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Is-it-possible-to-generate-a-quot-ticket-number-quot-style/m-p/249658#M1783</link>
      <description>&lt;P&gt;You could build a lookup process, which would link the event_id to a more user-friendly ticket number. I am sure that it could be automated with a python script, or some other form of scripting. &lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2016 02:28:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Is-it-possible-to-generate-a-quot-ticket-number-quot-style/m-p/249658#M1783</guid>
      <dc:creator>tezkpk</dc:creator>
      <dc:date>2016-10-20T02:28:58Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to generate a "ticket number" style reference for a notable event?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Is-it-possible-to-generate-a-quot-ticket-number-quot-style/m-p/249659#M1784</link>
      <description>&lt;P&gt;For now, I would check out the "Share Notable Event" action in the Actions dropdown per notable event.  This produces direct hyperlinks to the notable event with a copy-clipboard option.  While not a "ticket number", this link can be distributed in digital-friendly ways:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://server:8000/splunk-es/en-US/app/SplunkEnterpriseSecuritySuite/incident_review?form.srch=rule_id%3DDB9D6F9F-4BFD-4A81-8852-39474DCB9D56%40%40notable%40%405dc87d1d390c9c47b2a7de18d2cc7bc3&amp;amp;earliest=1477325415&amp;amp;latest=1477325417" target="_blank"&gt;https://server:8000/splunk-es/en-US/app/SplunkEnterpriseSecuritySuite/incident_review?form.srch=rule_id%3DDB9D6F9F-4BFD-4A81-8852-39474DCB9D56%40%40notable%40%405dc87d1d390c9c47b2a7de18d2cc7bc3&amp;amp;earliest=1477325415&amp;amp;latest=1477325417&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/169174-screen-shot-2016-10-24-at-113900-am.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:32:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Is-it-possible-to-generate-a-quot-ticket-number-quot-style/m-p/249659#M1784</guid>
      <dc:creator>hazekamp</dc:creator>
      <dc:date>2020-09-29T11:32:17Z</dc:date>
    </item>
  </channel>
</rss>

