Knowledge Management

Additional field - event acknowledgment

kkuminsky
Path Finder

Is there a way to add an additional field to every event for acknowledgment?

I'm analyzing failed login attempts. As some of them happened for a known reason I'd like to mark them somehow in the final report.

Tags (2)

araitz
Splunk Employee
Splunk Employee

Yes, we need this!!!

0 Karma

ftk
Motivator

I am doing something similar to what you're trying to do -- basically I am tagging events in splunk with change ticket numbers using lookups. You should be able to tune this to your requirements:

http://answers.splunk.com/questions/3982/correlate-and-tag-splunk-events-with-change-control-tickets

netwrkr
Communicator

This sure would be a nice feature.

Get Updates on the Splunk Community!

Developer Spotlight with Brett Adams

In our third Spotlight feature, we're excited to shine a light on Brett—a Splunk consultant, innovative ...

Index This | What can you do to make 55,555 equal 500?

April 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...