<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to label the attributing events additional fields which can associate the correlation search and drill-down sear in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/how-to-label-the-attributing-events-additional-fields-which-can/m-p/673309#M230552</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263755"&gt;@jaro&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;to see a field in the fields of a Notable (in the Incident Review dashboard) you have to check if this field is displayed in the Notable event (running index=notable search=your_correlation_search),&lt;/P&gt;&lt;P&gt;if not, probably isn't displayed in the output of the correlation search: manually run your correlation search and see if the field is displayed, if not add it to the correlation Search.&lt;/P&gt;&lt;P&gt;One additional hint: don't modify the Correlation Search, but clone it and modify and enable only the cloned one.&lt;/P&gt;&lt;P&gt;If the field is present in the Notable event, you have also to check if it's present in the default visible fields, that you can find these configurations at [Configure &amp;gt; Incident management &amp;gt; Incident Review Settings] in the section Incident Review - Event Attributes.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Fri, 05 Jan 2024 07:53:08 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2024-01-05T07:53:08Z</dc:date>
    <item>
      <title>how to label the attributing events additional fields which can associate the correlation search and drill-down search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-label-the-attributing-events-additional-fields-which-can/m-p/673300#M230550</link>
      <description>&lt;P&gt;Here are the screenshots:&lt;/P&gt;&lt;P&gt;In incident review setting, I have already labeled signature:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jaro_0-1704421786405.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28774i703E498C62F77EFD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jaro_0-1704421786405.png" alt="jaro_0-1704421786405.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Then in Correlation Search content setting, also I have setting the search query which could result in fields with signature. This search can be run normally in search head and show the result I want.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jaro_1-1704421940091.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28775i60596670346B4E42/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jaro_1-1704421940091.png" alt="jaro_1-1704421940091.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But here related to drill-down search or description, this $signature$ can not show in notable of incident review:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jaro_2-1704422095632.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28776i0D55421F633DE6C1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jaro_2-1704422095632.png" alt="jaro_2-1704422095632.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jaro_3-1704422192557.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28777iC6615CB3413E7700/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jaro_3-1704422192557.png" alt="jaro_3-1704422192557.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;May I ask how to solve this issue?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2024 02:40:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-label-the-attributing-events-additional-fields-which-can/m-p/673300#M230550</guid>
      <dc:creator>jaro</dc:creator>
      <dc:date>2024-01-05T02:40:06Z</dc:date>
    </item>
    <item>
      <title>Re: how to label the attributing events additional fields which can associate the correlation search and drill-down sear</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-label-the-attributing-events-additional-fields-which-can/m-p/673309#M230552</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263755"&gt;@jaro&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;to see a field in the fields of a Notable (in the Incident Review dashboard) you have to check if this field is displayed in the Notable event (running index=notable search=your_correlation_search),&lt;/P&gt;&lt;P&gt;if not, probably isn't displayed in the output of the correlation search: manually run your correlation search and see if the field is displayed, if not add it to the correlation Search.&lt;/P&gt;&lt;P&gt;One additional hint: don't modify the Correlation Search, but clone it and modify and enable only the cloned one.&lt;/P&gt;&lt;P&gt;If the field is present in the Notable event, you have also to check if it's present in the default visible fields, that you can find these configurations at [Configure &amp;gt; Incident management &amp;gt; Incident Review Settings] in the section Incident Review - Event Attributes.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2024 07:53:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-label-the-attributing-events-additional-fields-which-can/m-p/673309#M230552</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-01-05T07:53:08Z</dc:date>
    </item>
    <item>
      <title>Re: how to label the attributing events additional fields which can associate the correlation search and drill-down sear</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-label-the-attributing-events-additional-fields-which-can/m-p/673326#M230557</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;.&amp;nbsp; ---&lt;SPAN&gt;to check if this field is displayed in the Notable event (running index=notable search=your_correlation_search), yes, I have display the result "signature" in the search I ran. However, the below description can not show the field value "signature" I search in correlation search as $signature$.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also I have tried eval other name equal to field signature, still nothing.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2024 09:50:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-label-the-attributing-events-additional-fields-which-can/m-p/673326#M230557</guid>
      <dc:creator>jaro</dc:creator>
      <dc:date>2024-01-05T09:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: how to label the attributing events additional fields which can associate the correlation search and drill-down sear</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-label-the-attributing-events-additional-fields-which-can/m-p/673328#M230558</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263755"&gt;@jaro&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;if the field is in the Notable index, can be displayed.&lt;/P&gt;&lt;P&gt;Did you checked if it's in the visualized fields?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2024 10:11:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-label-the-attributing-events-additional-fields-which-can/m-p/673328#M230558</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-01-05T10:11:44Z</dc:date>
    </item>
    <item>
      <title>Re: how to label the attributing events additional fields which can associate the correlation search and drill-down sear</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-label-the-attributing-events-additional-fields-which-can/m-p/673482#M230618</link>
      <description>&lt;P&gt;It's OKAY now. In next triggered notable, it displayed.&amp;nbsp;Thank you&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 03:39:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-label-the-attributing-events-additional-fields-which-can/m-p/673482#M230618</guid>
      <dc:creator>jaro</dc:creator>
      <dc:date>2024-01-08T03:39:02Z</dc:date>
    </item>
    <item>
      <title>Re: how to label the attributing events additional fields which can associate the correlation search and drill-down sear</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-label-the-attributing-events-additional-fields-which-can/m-p/673495#M230619</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263755"&gt;@jaro&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 07:18:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-label-the-attributing-events-additional-fields-which-can/m-p/673495#M230619</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-01-08T07:18:04Z</dc:date>
    </item>
  </channel>
</rss>

