<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Enterprise Security Notable Event Title Not Working in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Notable-Event-Title-Not-Working/m-p/464433#M6861</link>
    <description>&lt;P&gt;Notable link is on Lower right... under Adaptive Responses..&lt;/P&gt;</description>
    <pubDate>Mon, 30 Mar 2020 20:27:37 GMT</pubDate>
    <dc:creator>memarshall63</dc:creator>
    <dc:date>2020-03-30T20:27:37Z</dc:date>
    <item>
      <title>Splunk Enterprise Security Notable Event Title Not Working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Notable-Event-Title-Not-Working/m-p/464431#M6859</link>
      <description>&lt;P&gt;Hello all, &lt;/P&gt;

&lt;P&gt;I'm currently stumped in trying to figure out why my notable event token is not working. I verified the field that the token uses exist in the correlation search result (example below).&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; | stats dc("dest") AS host_count
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/8625iD4BE5E63FFF4D945/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Notable Event Title:&lt;/P&gt;

&lt;P&gt;on $host_count$ hosts.&lt;/P&gt;

&lt;P&gt;The token for some reason doesn't expand and output the number 13...&lt;/P&gt;

&lt;P&gt;Can you guys help in figuring this out? Thank you for your time. &lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2020 20:14:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Notable-Event-Title-Not-Working/m-p/464431#M6859</guid>
      <dc:creator>mpham07</dc:creator>
      <dc:date>2020-03-30T20:14:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security Notable Event Title Not Working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Notable-Event-Title-Not-Working/m-p/464432#M6860</link>
      <description>&lt;P&gt;When you see the incident in Incident Review -- Have you ever looked at the 'notable' drill down?&lt;/P&gt;

&lt;P&gt;This will drill down to the raw event in the notables index.   Check to make sure your field is there.&lt;/P&gt;

&lt;P&gt;Sometimes field names get manipulated in the notable so they don't collide with the fields in the notable index.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2020 20:26:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Notable-Event-Title-Not-Working/m-p/464432#M6860</guid>
      <dc:creator>memarshall63</dc:creator>
      <dc:date>2020-03-30T20:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security Notable Event Title Not Working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Notable-Event-Title-Not-Working/m-p/464433#M6861</link>
      <description>&lt;P&gt;Notable link is on Lower right... under Adaptive Responses..&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2020 20:27:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Notable-Event-Title-Not-Working/m-p/464433#M6861</guid>
      <dc:creator>memarshall63</dc:creator>
      <dc:date>2020-03-30T20:27:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security Notable Event Title Not Working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Notable-Event-Title-Not-Working/m-p/464434#M6862</link>
      <description>&lt;P&gt;Hi @memarshall63,&lt;/P&gt;

&lt;P&gt;Thanks for the quick response. This correlation search isn't using a datamodel or tstats and we're just searching against a custom index (old searches previously made by someone else...)  &lt;/P&gt;

&lt;P&gt;So I verified the drill down search has the same field. I've been ripping my hair out trying different stuff to get it to work but no luck ;__; It's not a big deal but it bugs the heck outta me. &lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2020 20:34:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Notable-Event-Title-Not-Working/m-p/464434#M6862</guid>
      <dc:creator>mpham07</dc:creator>
      <dc:date>2020-03-30T20:34:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security Notable Event Title Not Working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Notable-Event-Title-Not-Working/m-p/464435#M6863</link>
      <description>&lt;P&gt;So you're saying that a token in the "Drill-down Name" field of your Notable isn't working, but the same token when used in the "Drill-down Search" field gets passed correctly to the drill-down search?&lt;/P&gt;

&lt;P&gt;If that's what you're seeing -- then that is a bit nasty.. I'd start to wonder whether your browser is telling you the truth?   Clear browser cache?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2020 20:47:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Notable-Event-Title-Not-Working/m-p/464435#M6863</guid>
      <dc:creator>memarshall63</dc:creator>
      <dc:date>2020-03-30T20:47:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security Notable Event Title Not Working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Notable-Event-Title-Not-Working/m-p/464436#M6864</link>
      <description>&lt;P&gt;I cleared my browser cache and history but no luck. &lt;/P&gt;

&lt;P&gt;There are two tokens used in the Notable Event title, it's just the host_count field doesn't work for some reason. Initially I didn't use the host_count in the drill down search title, but I just tested it just now and that also doesn't work for some reason. I only pass the working token to the actual drill down search and title and that works fine. &lt;/P&gt;

&lt;P&gt;The issue just seems to be the host_count field. &lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:49:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Notable-Event-Title-Not-Working/m-p/464436#M6864</guid>
      <dc:creator>mpham07</dc:creator>
      <dc:date>2020-09-30T04:49:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security Notable Event Title Not Working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Notable-Event-Title-Not-Working/m-p/464437#M6865</link>
      <description>&lt;P&gt;hmm..  tough to say.   At least you're saying that the token doesn't work no matter where you try to use it.   That gets us back into the normal territory.&lt;/P&gt;

&lt;P&gt;I'm confused how you're using a stats command, but also generating the rest of the notable fields.   Maybe you can post a few more details of your search output, or the notable that comes out of it.   &lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2020 21:35:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Notable-Event-Title-Not-Working/m-p/464437#M6865</guid>
      <dc:creator>memarshall63</dc:creator>
      <dc:date>2020-03-30T21:35:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security Notable Event Title Not Working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Notable-Event-Title-Not-Working/m-p/464438#M6866</link>
      <description>&lt;P&gt;So the correlation search looks like this:&lt;/P&gt;

&lt;P&gt;index=test sourcetype="example" | stats dc(dest) AS host_count, values("dest") AS host_name, values("match_hash") AS hash, values("path") AS file_path by "intel_name"&lt;/P&gt;

&lt;P&gt;So it outputs a table like this:&lt;BR /&gt;
intel_name | host_count | host_name | hash | file_path&lt;/P&gt;

&lt;P&gt;All of the fields are in the notable index when I checked. I used the hash field token just fine in the notable event title - not sure what's going on...&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:50:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Notable-Event-Title-Not-Working/m-p/464438#M6866</guid>
      <dc:creator>mpham07</dc:creator>
      <dc:date>2020-09-30T04:50:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security Notable Event Title Not Working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Notable-Event-Title-Not-Working/m-p/464439#M6867</link>
      <description>&lt;P&gt;Does your resulting table only have a single row in it?  Or are there multiple rows?   &lt;/P&gt;

&lt;P&gt;dc returns a single value, but I think values returns a multi-value field.&lt;BR /&gt;
I'm just shooting in the dark at this point but maybe:&lt;/P&gt;

&lt;P&gt;Change dc(dest) AS host count  -&amp;gt;   values(dest) AS host count&lt;BR /&gt;
Swap the field names -&amp;gt; dc(dest) AS hash values("match_hash") as host_count&lt;BR /&gt;
Remove the "by "intel_name". &lt;BR /&gt;
I did notice that you seem to be quoting the other fields, but not dc(dest)?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:50:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Notable-Event-Title-Not-Working/m-p/464439#M6867</guid>
      <dc:creator>memarshall63</dc:creator>
      <dc:date>2020-09-30T04:50:24Z</dc:date>
    </item>
  </channel>
</rss>

