Splunk Enterprise Security

Enterprise Security 3.0 - Customize Incident Review Fields

panovattack
Communicator

How do you add a custom field to the Incident Review dashboard in ES 3.0? I found a solution for 2.4, but does not seem to carry over to 3.0.

Tags (1)
1 Solution

panovattack
Communicator

Figured this out - edit the incident_settings located at /SA-ThreatIntelligence/alerts/log_review/incident_review

View solution in original post

0 Karma

panovattack
Communicator

Figured this out - edit the incident_settings located at /SA-ThreatIntelligence/alerts/log_review/incident_review

0 Karma

japala
Path Finder

i am not able to find this alerts directory under this SA-ThreatIntelligence application. any thoughts??

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...