<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Would like to know best path to reach Splunk Enterprise 8.0.X and Splunk ES 6.1.x in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/SPLUNK-ES-Notable-Event-Closure/m-p/494043#M8464</link>
    <description>&lt;P&gt;Thanks @richgalloway for quick response.&lt;/P&gt;

&lt;P&gt;Yes I understand my upgrade path is not direct. &lt;/P&gt;

&lt;P&gt;The problem is first  if I upgrade Splunk ES to 5.x it doesn’t support Current version of  Enterprise or &lt;/P&gt;

&lt;P&gt;First If I upgrade Splunk Enterprise to lets say 7.3.3 Then ES current version doesn’t support.&lt;/P&gt;

&lt;P&gt;I am now confused what to upgrade first.&lt;/P&gt;</description>
    <pubDate>Tue, 12 May 2020 19:04:00 GMT</pubDate>
    <dc:creator>thambisetty</dc:creator>
    <dc:date>2020-05-12T19:04:00Z</dc:date>
    <item>
      <title>SPLUNK ES Notable Event Closure</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/SPLUNK-ES-Notable-Event-Closure/m-p/494041#M8462</link>
      <description>&lt;P&gt;When closing a notable event in SPLUNK Enterprise Security, there are typically the following fields available&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Status&lt;/LI&gt;
&lt;LI&gt;Change urgency&lt;/LI&gt;
&lt;LI&gt;Owner&lt;/LI&gt;
&lt;LI&gt;Description Summary/Notes&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Is there a way to add a new field with a custom drop down into the closure of the notable event. For example (using the example above), I would create a new field called Category with a drop down list to select the type of category.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Status&lt;/LI&gt;
&lt;LI&gt;Change urgency&lt;/LI&gt;
&lt;LI&gt;Owner&lt;/LI&gt;
&lt;LI&gt;Category&lt;/LI&gt;
&lt;LI&gt;Description Summary/Notes&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Sun, 07 Jun 2020 16:20:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/SPLUNK-ES-Notable-Event-Closure/m-p/494041#M8462</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-06-07T16:20:23Z</dc:date>
    </item>
    <item>
      <title>Re: Would like to know best path to reach Splunk Enterprise 8.0.X and Splunk ES 6.1.x</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/SPLUNK-ES-Notable-Event-Closure/m-p/494042#M8463</link>
      <description>&lt;P&gt;Your upgrade path will not be direct.  You will need to upgrade ES to version 5 before installing ES 6. See &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.3/Installation/HowtoupgradeSplunk#Upgrade_paths_to_version_8.0"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.3/Installation/HowtoupgradeSplunk#Upgrade_paths_to_version_8.0&lt;/A&gt; for the path to upgrade ES.&lt;BR /&gt;&lt;BR /&gt;
Be sure to run the Splunk Platform Readiness app (&lt;A href="https://splunkbase.splunk.com/app/4698/"&gt;https://splunkbase.splunk.com/app/4698/&lt;/A&gt;) before installing Splunk 8 to make sure all of your Python scripts will be compatible.&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2020 18:25:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/SPLUNK-ES-Notable-Event-Closure/m-p/494042#M8463</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-05-12T18:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: Would like to know best path to reach Splunk Enterprise 8.0.X and Splunk ES 6.1.x</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/SPLUNK-ES-Notable-Event-Closure/m-p/494043#M8464</link>
      <description>&lt;P&gt;Thanks @richgalloway for quick response.&lt;/P&gt;

&lt;P&gt;Yes I understand my upgrade path is not direct. &lt;/P&gt;

&lt;P&gt;The problem is first  if I upgrade Splunk ES to 5.x it doesn’t support Current version of  Enterprise or &lt;/P&gt;

&lt;P&gt;First If I upgrade Splunk Enterprise to lets say 7.3.3 Then ES current version doesn’t support.&lt;/P&gt;

&lt;P&gt;I am now confused what to upgrade first.&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2020 19:04:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/SPLUNK-ES-Notable-Event-Closure/m-p/494043#M8464</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-05-12T19:04:00Z</dc:date>
    </item>
    <item>
      <title>Re: Would like to know best path to reach Splunk Enterprise 8.0.X and Splunk ES 6.1.x</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/SPLUNK-ES-Notable-Event-Closure/m-p/494044#M8465</link>
      <description>&lt;P&gt;ES can run on an unsupported version of Splunk for a short time.  "Short" means "until we upgrade again later today".&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2020 19:18:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/SPLUNK-ES-Notable-Event-Closure/m-p/494044#M8465</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-05-12T19:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK ES Notable Event Closure</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/SPLUNK-ES-Notable-Event-Closure/m-p/520478#M9285</link>
      <description>&lt;P&gt;answers are not related to question. I think this is the problem after migration from answers.splunk.com to community.splunk.com&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 20 Sep 2020 09:49:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/SPLUNK-ES-Notable-Event-Closure/m-p/520478#M9285</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-09-20T09:49:14Z</dc:date>
    </item>
  </channel>
</rss>

