Splunk Enterprise Security

ES Investigation Note Formatting

packetrider
Engager

When you create notes in Splunk ES you can format the notes with tabs and carriage returns.  When the note saves and is shown in a slide or expanded on the timeline the text is all mashed together.  Is there a way to retain the note formatting in the slides/timeline?

Labels (1)

Kaizen
New Member

Hello,

Was a solution ever found?  I am experiencing this, a Note in an investigation is easier to read in Edit mode than after its published.  When published, it looks like one runon sentence, no spacing, no formatting.

Thanks in advance!

Kai

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...