Splunk Enterprise Security

Embed Field values in Title for a correlation search

bharathkumarnec
Communicator

Hi,

In Splunk Enterprise Security, in order to embed field values in a title we need to use "$fieldname$" but in the ITSI i can see in the documentation that it is "%fieldname%", the way of representing the fieldvalues in the title differs in both cases??

Thanks,

BK

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!