Hi,
I'm trying to see if there's a way to add additional/custom fields in Incident Review.
Is there much room for customisation? All I've seen thus far is adding event attributes via Incident Review settings.
Sorry this is rather vague - Just looking to find ways to customize these settings on the basis of different notable events.
Thanks,
Adam.
what sort of customization are you looking to do per notable? Have you looked at http://www.georgestarcher.com/splunk-enterprise-security-enhancing-incident-review/ to suggest linking a ticketId to adaptive response?