Splunk Enterprise Security

Help creating a table that shows specific notable information

LionWolf
Explorer

Hello Community,

 

I'm working on a search for a dashboard panel and I need some help.

I'm looking to get the owner, search_name, status_label, and the last comment.

The search I have so far is below:


`notable`
| where owner =="User1" OR owner=="User2" OR owner=="User3" OR owner=="User4" OR owner=="User5" OR owner=="User6"
| where status_label=="Ready for Review" OR status_label=="Closed: False Positive" OR status_label=="Pending" OR status_label=="Closed: Valid - Remediated"
| stats earliest(owner) AS Analyst, earliest(search_name) AS "Alert Name", latest(status_label) AS Status, latest(comment) AS Summary

Labels (1)
Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

The stats command is giving you a single result for the whole search - perhaps you need to use a BY clause?

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

In what way does this not give you what you have asked for?

0 Karma

LionWolf
Explorer

Hello ITWhisperer,

I only get one notable event, even for 30 days. I need all of the notable events that have been worked on, and that currently have the status_label of "Ready for Review", "Closed: False Positive", "Pending", "Closed: Valid - Remediated"

 

I thought this search should have returned the results I needed but it isn't.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

The stats command is giving you a single result for the whole search - perhaps you need to use a BY clause?

0 Karma

LionWolf
Explorer

The by clause worked! Thank you so much!

0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...