- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can I add comment field as table attribute in incident review page. For that what would be field name so I can map it with my custom lable. Where the field name I can find for owner & status also.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


http://dev.splunk.com/view/enterprise-security/SP-CAAAFBA will probably help you find information about the comment field, and http://docs.splunk.com/Documentation/ES/5.0.0/Admin/Customizenotables#Add_a_field_to_the_notable_eve... covers in more detail and more up-to-date how to get an additional field to appear on incident review.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


http://dev.splunk.com/view/enterprise-security/SP-CAAAFBA will probably help you find information about the comment field, and http://docs.splunk.com/Documentation/ES/5.0.0/Admin/Customizenotables#Add_a_field_to_the_notable_eve... covers in more detail and more up-to-date how to get an additional field to appear on incident review.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Answer for your question is below
https://answers.splunk.com/answers/298999/splunk-app-for-enterprise-security-how-to-add-addi.html
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Still, I don't find the field name for comment label. Thanks for your answer I understand how to add new field.
