I am looking to include certain fields that are in the contributing events for a certain Correlation Search/Notable.
The documentation I found: https://docs.splunk.com/Documentation/ES/latest/Admin/Customizenotables
This basically says you can add additional fields, but this will apply to all Notables in Incident Review.
My question is if other notables that have different correlation searches don't include an additional field what happens?
Does it just not get displayed in that Notable or does it list the field with a null value in the Incident Review Dashboard?
Hi @Ryanjp96,
to display a field in the additional ields of the Incident Review dashboard you have to insert the fields in the correlation searches that generate notables, in this way these fields are displayable.
If they aren't present in a notable generated by a Correlation Search without this field it isn't only visualized in the additional fields, no Null value.
Ciao.
Giuseppe
Awesome thanks for your help @gcusello !
Hi @Ryanjp96,
to display a field in the additional ields of the Incident Review dashboard you have to insert the fields in the correlation searches that generate notables, in this way these fields are displayable.
If they aren't present in a notable generated by a Correlation Search without this field it isn't only visualized in the additional fields, no Null value.
Ciao.
Giuseppe
Hi @Ryanjp96 ,
good for you, see next time!
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated 😉