<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to reference a token name with spaces in it for notable event action? (ES Correlation Searches) in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-reference-a-token-name-with-spaces-in-it-for-notable/m-p/375590#M3745</link>
    <description>&lt;P&gt;I'm working on creating new notable events in Enterprise Security. In the notable event alert action, I'm trying to add field values to the title so that it's easier for analysts to differentiate alerts on the Incident Review dashboard. I've noticed that when the field name &lt;EM&gt;does not&lt;/EM&gt; contain spaces, I can just reference the field name using its token, e.g. &lt;CODE&gt;Excessive failed logins from $src_ip$&lt;/CODE&gt;, and it works fine. The notable event will pop into the Incident Review dashboard with the expected title of, "Excessive failed logins from 123.456.789.0"&lt;/P&gt;

&lt;P&gt;However, some of my searches have renames at the end, like &lt;CODE&gt;rename src_ip as "Source IP"&lt;/CODE&gt;.  I can't seem to get the Incident Review dashboard to display the field value when the field name contains spaces. What's the correct syntax to reference a token where the field name contains spaces in it?&lt;/P&gt;

&lt;P&gt;An obvious workaround would be to remove the renames so that none of the field names contain spaces, but if referencing them with spaces is possible, I would like to know how. I was unable to find an answer in the documentation or online.&lt;/P&gt;</description>
    <pubDate>Fri, 04 May 2018 19:59:55 GMT</pubDate>
    <dc:creator>masonmorales</dc:creator>
    <dc:date>2018-05-04T19:59:55Z</dc:date>
    <item>
      <title>How to reference a token name with spaces in it for notable event action? (ES Correlation Searches)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-reference-a-token-name-with-spaces-in-it-for-notable/m-p/375590#M3745</link>
      <description>&lt;P&gt;I'm working on creating new notable events in Enterprise Security. In the notable event alert action, I'm trying to add field values to the title so that it's easier for analysts to differentiate alerts on the Incident Review dashboard. I've noticed that when the field name &lt;EM&gt;does not&lt;/EM&gt; contain spaces, I can just reference the field name using its token, e.g. &lt;CODE&gt;Excessive failed logins from $src_ip$&lt;/CODE&gt;, and it works fine. The notable event will pop into the Incident Review dashboard with the expected title of, "Excessive failed logins from 123.456.789.0"&lt;/P&gt;

&lt;P&gt;However, some of my searches have renames at the end, like &lt;CODE&gt;rename src_ip as "Source IP"&lt;/CODE&gt;.  I can't seem to get the Incident Review dashboard to display the field value when the field name contains spaces. What's the correct syntax to reference a token where the field name contains spaces in it?&lt;/P&gt;

&lt;P&gt;An obvious workaround would be to remove the renames so that none of the field names contain spaces, but if referencing them with spaces is possible, I would like to know how. I was unable to find an answer in the documentation or online.&lt;/P&gt;</description>
      <pubDate>Fri, 04 May 2018 19:59:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-reference-a-token-name-with-spaces-in-it-for-notable/m-p/375590#M3745</guid>
      <dc:creator>masonmorales</dc:creator>
      <dc:date>2018-05-04T19:59:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to reference a token name with spaces in it for notable event action? (ES Correlation Searches)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-reference-a-token-name-with-spaces-in-it-for-notable/m-p/375591#M3746</link>
      <description>&lt;P&gt;I'd suggest removing the renames and then use the incident review settings page to provide user-facing names for the custom fields. &lt;A href="http://docs.splunk.com/Documentation/ES/5.0.0/Admin/Customizenotables#Add_a_field_to_the_notable_event_details"&gt;http://docs.splunk.com/Documentation/ES/5.0.0/Admin/Customizenotables#Add_a_field_to_the_notable_event_details&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 May 2018 20:07:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-reference-a-token-name-with-spaces-in-it-for-notable/m-p/375591#M3746</guid>
      <dc:creator>smoir_splunk</dc:creator>
      <dc:date>2018-05-04T20:07:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to reference a token name with spaces in it for notable event action? (ES Correlation Searches)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-reference-a-token-name-with-spaces-in-it-for-notable/m-p/375592#M3747</link>
      <description>&lt;P&gt;Accepted as this is what I ended up doing.  &lt;/P&gt;</description>
      <pubDate>Fri, 11 May 2018 00:20:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-reference-a-token-name-with-spaces-in-it-for-notable/m-p/375592#M3747</guid>
      <dc:creator>masonmorales</dc:creator>
      <dc:date>2018-05-11T00:20:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to reference a token name with spaces in it for notable event action? (ES Correlation Searches)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-reference-a-token-name-with-spaces-in-it-for-notable/m-p/375593#M3748</link>
      <description>&lt;P&gt;Sorry I didn't have an SPL workaround for you, mason &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 11 May 2018 00:21:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-reference-a-token-name-with-spaces-in-it-for-notable/m-p/375593#M3748</guid>
      <dc:creator>smoir_splunk</dc:creator>
      <dc:date>2018-05-11T00:21:39Z</dc:date>
    </item>
  </channel>
</rss>

