Security

Edit Notable Event Name

Nawab
Communicator

When we create a notable, we want to use certain fields such as source IP and destination IP,

 

When I create the rule and add these fields as $src$ and $dest$ in enterprise security 7.0.0 it works, but in 7.3.0 it does not show any result.

Nawab_0-1710142586233.png

 

0 Karma

Nawab
Communicator

also, the drill down search is not available as well

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Nawab ,

did you configured a drilldown search for your Correlation Search?

it's not automatic.

Ciao.

Giuseppe

0 Karma

Nawab
Communicator

yes i have configured drill down search

0 Karma

Nawab
Communicator

yes i have these fields in my coorelation search, but when i set notable name, it only shows the rule name instead of fileds i have added.

 

test_alert $src$ $dest$ $user$

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Nawab,

in this way you can display these fields in the Incident Review dashboard, I'm not sure that's possible to have a dinamic Rule Name!

Anyway, why?

having different Rule Names you cannot have statistic and grouping of Rules.

It's instead very important to have the needed information in the Incident Review dashboard.

Ciao,

Giuseppe

0 Karma

Nawab
Communicator

Not a dynamic rule name but notable name, where in the alert it will refelect the details on while alert was triggered,

rule name : test rule

 

notable name: test rule triggered on $src$ and $dest$

new notable name: test rule triggered on 10.10.1.1 and 10.10.1.2

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Nawab,

sorry!

I misunderstood, but anyway, also the Notable name, for my knowldge cannot be dinamic.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Nawab,

to display additional fields in the Incident Review dashboard, you have to chech if these fields are present in the Correlation Search that creates the Notable.

If they are, you can customize your dashboard in [ Configure > Incident Management > Incident Review Settings > Incient Review - Table Attributes ].

Ciao.

Giuseppe

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...