Splunk Enterprise Security

Adding to 'Additional Fields' In Incident Review

adam_dixon95
Explorer

Hi,

I'm trying to see if there's a way to add additional/custom fields in Incident Review.

Is there much room for customisation? All I've seen thus far is adding event attributes via Incident Review settings.

Sorry this is rather vague - Just looking to find ways to customize these settings on the basis of different notable events.

Thanks,

Adam.

0 Karma

lakshman239
Influencer

what sort of customization are you looking to do per notable? Have you looked at http://www.georgestarcher.com/splunk-enterprise-security-enhancing-incident-review/ to suggest linking a ticketId to adaptive response?

0 Karma
Get Updates on the Splunk Community!

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...