- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Adding to 'Additional Fields' In Incident Review

adam_dixon95
Explorer
04-15-2019
09:47 AM
Hi,
I'm trying to see if there's a way to add additional/custom fields in Incident Review.
Is there much room for customisation? All I've seen thus far is adding event attributes via Incident Review settings.
Sorry this is rather vague - Just looking to find ways to customize these settings on the basis of different notable events.
Thanks,
Adam.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

lakshman239
Influencer
04-23-2019
05:09 AM
what sort of customization are you looking to do per notable? Have you looked at http://www.georgestarcher.com/splunk-enterprise-security-enhancing-incident-review/ to suggest linking a ticketId to adaptive response?
