Splunk Enterprise Security

ES: How to edit "Description" under Incident Review?

morethanyell
Builder

Hi,

My folks from cybersecurity wishes to display the epoch time under Description to human readable time. I can't seem to find it. I tried the Incident Review Settings but to no avail.

The screenshot below points to the value which I would like to modify.

Thanks in advance!alt text

0 Karma
1 Solution

lakshman239
SplunkTrust
SplunkTrust

The description field comes from the notable adaptive response action as part of creating correlation search https://docs.splunk.com/Documentation/ES/5.3.0/Tutorials/NewCorrelationSearch

So, if you want to display a human readable time, your search should have a field, say, daytime and you can display it using $daytime$ within the description.

View solution in original post

0 Karma

lakshman239
SplunkTrust
SplunkTrust

The description field comes from the notable adaptive response action as part of creating correlation search https://docs.splunk.com/Documentation/ES/5.3.0/Tutorials/NewCorrelationSearch

So, if you want to display a human readable time, your search should have a field, say, daytime and you can display it using $daytime$ within the description.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...