Security & the Enterprise
Much secured. So patch!

Incident Review - Table Attributes ES

New Member

Is there a way to put 2 field names in the Incident Review Table attributes so that it looks at 2 different fields to populate 1 field?  For example  Label=FW Action  Field = action and fw_action.  We have events that use both field names but don't want to have 2 separate columns.

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.