Security

Why didn't event attributes show?

maurobissante
Explorer

Hi guys,

I have an issue with the Enterprise Security APP where I try to add a new Event Attributes (user) that is correctly populated and available in the event (in the Contributing Events search) and in the datamodel, but it is not showed in the Incident Review table.

It seems that It can be an error with the alias of the field because in the data raw we see that the field name is "userPrincipalName" but in the Interesting Field we have "user" (the field that is now showed in the Incident Review table).

We also tried adding the userPrincipalName field to the Event Attributes but also this field is not populated.

How can we show that field in the table?

Thanks,

Mauro   

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...