How to Mark ES incident or alert as True/False Positive in Splunk cloud


Hi Team,

Requirement : ES incident/Alerts  should be mark as True Positive or False Positive as verdict .

Please help how I can fulfill this requirement,.

Is there any custom field configuration or any drop down list can be configured ?

Labels (1)
0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!