Splunk Enterprise Security

ES Investigation Note Formatting

packetrider
Engager

When you create notes in Splunk ES you can format the notes with tabs and carriage returns.  When the note saves and is shown in a slide or expanded on the timeline the text is all mashed together.  Is there a way to retain the note formatting in the slides/timeline?

Labels (1)

Kaizen
New Member

Hello,

Was a solution ever found?  I am experiencing this, a Note in an investigation is easier to read in Edit mode than after its published.  When published, it looks like one runon sentence, no spacing, no formatting.

Thanks in advance!

Kai

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...

Federated Search for CloudWatch Unified Data Store Is Generally Available

As organizations modernize their cloud environments, AWS workloads generate more security, operational, and ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...