Security

How to achieve custom fields in incident review dashboard?

gcusello
SplunkTrust
SplunkTrust

Hi at all,

I tried to customize the Incident Review Dashboard to display some additional fields as user, src or dest, as described in the Enterprise Security Admin course.

At first I found that to have these fields in the Additional Fields, I must add them also to the main dashboard columns, otherwise the additional field isn't displayed, and this is already something not documented.

But the problem is that this field is displayed only for some Notables and not for all (as i waited),
I also found that the src field is present in all the Notables (except risk based notables), instead user and dest (the most important is user that should be always present) sometimes are present and sometimes not.
I supposed that the issue was in the Correlation Search that doesn't add this field to the Notable but opening the Notable with the contributing events link the field is always present.

Had someone else experienced this issue?

Thank you for your attention.
Ciao.
Giuseppe

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi at all,

the solution was to modify Correlation Searches to have the fields to display in the Notable events.

Thanks to Splunk Support.

ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi at all,

the solution was to modify Correlation Searches to have the fields to display in the Notable events.

Thanks to Splunk Support.

ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability As businesses scale ...