- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Edit Notable Event Name
When we create a notable, we want to use certain fields such as source IP and destination IP,
When I create the rule and add these fields as $src$ and $dest$ in enterprise security 7.0.0 it works, but in 7.3.0 it does not show any result.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
also, the drill down search is not available as well
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @Nawab ,
did you configured a drilldown search for your Correlation Search?
it's not automatic.
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yes i have configured drill down search
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yes i have these fields in my coorelation search, but when i set notable name, it only shows the rule name instead of fileds i have added.
test_alert $src$ $dest$ $user$
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @Nawab,
in this way you can display these fields in the Incident Review dashboard, I'm not sure that's possible to have a dinamic Rule Name!
Anyway, why?
having different Rule Names you cannot have statistic and grouping of Rules.
It's instead very important to have the needed information in the Incident Review dashboard.
Ciao,
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Not a dynamic rule name but notable name, where in the alert it will refelect the details on while alert was triggered,
rule name : test rule
notable name: test rule triggered on $src$ and $dest$
new notable name: test rule triggered on 10.10.1.1 and 10.10.1.2
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @Nawab,
sorry!
I misunderstood, but anyway, also the Notable name, for my knowldge cannot be dinamic.
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @Nawab,
to display additional fields in the Incident Review dashboard, you have to chech if these fields are present in the Correlation Search that creates the Notable.
If they are, you can customize your dashboard in [ Configure > Incident Management > Incident Review Settings > Incient Review - Table Attributes ].
Ciao.
Giuseppe
