<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding to 'Additional Fields' In Incident Review in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adding-to-Additional-Fields-In-Incident-Review/m-p/416513#M5028</link>
    <description>&lt;P&gt;what sort of customization are you looking to do per notable? Have you looked at &lt;A href="http://www.georgestarcher.com/splunk-enterprise-security-enhancing-incident-review/"&gt;http://www.georgestarcher.com/splunk-enterprise-security-enhancing-incident-review/&lt;/A&gt; to suggest linking a ticketId to adaptive response?&lt;/P&gt;</description>
    <pubDate>Tue, 23 Apr 2019 12:09:49 GMT</pubDate>
    <dc:creator>lakshman239</dc:creator>
    <dc:date>2019-04-23T12:09:49Z</dc:date>
    <item>
      <title>Adding to 'Additional Fields' In Incident Review</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adding-to-Additional-Fields-In-Incident-Review/m-p/416512#M5027</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I'm trying to see if there's a way to add additional/custom fields in Incident Review.&lt;/P&gt;

&lt;P&gt;Is there much room for customisation? All I've seen thus far is adding event attributes via Incident Review settings. &lt;/P&gt;

&lt;P&gt;Sorry this is rather vague - Just looking to find ways to customize these settings on the basis of different notable events.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;

&lt;P&gt;Adam.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2019 16:47:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adding-to-Additional-Fields-In-Incident-Review/m-p/416512#M5027</guid>
      <dc:creator>adam_dixon95</dc:creator>
      <dc:date>2019-04-15T16:47:14Z</dc:date>
    </item>
    <item>
      <title>Re: Adding to 'Additional Fields' In Incident Review</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adding-to-Additional-Fields-In-Incident-Review/m-p/416513#M5028</link>
      <description>&lt;P&gt;what sort of customization are you looking to do per notable? Have you looked at &lt;A href="http://www.georgestarcher.com/splunk-enterprise-security-enhancing-incident-review/"&gt;http://www.georgestarcher.com/splunk-enterprise-security-enhancing-incident-review/&lt;/A&gt; to suggest linking a ticketId to adaptive response?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2019 12:09:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adding-to-Additional-Fields-In-Incident-Review/m-p/416513#M5028</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-04-23T12:09:49Z</dc:date>
    </item>
  </channel>
</rss>

