Splunk Enterprise Security

Help creating a table that shows specific notable information

LionWolf
Explorer

Hello Community,

 

I'm working on a search for a dashboard panel and I need some help.

I'm looking to get the owner, search_name, status_label, and the last comment.

The search I have so far is below:


`notable`
| where owner =="User1" OR owner=="User2" OR owner=="User3" OR owner=="User4" OR owner=="User5" OR owner=="User6"
| where status_label=="Ready for Review" OR status_label=="Closed: False Positive" OR status_label=="Pending" OR status_label=="Closed: Valid - Remediated"
| stats earliest(owner) AS Analyst, earliest(search_name) AS "Alert Name", latest(status_label) AS Status, latest(comment) AS Summary

Labels (1)
Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

The stats command is giving you a single result for the whole search - perhaps you need to use a BY clause?

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

In what way does this not give you what you have asked for?

0 Karma

LionWolf
Explorer

Hello ITWhisperer,

I only get one notable event, even for 30 days. I need all of the notable events that have been worked on, and that currently have the status_label of "Ready for Review", "Closed: False Positive", "Pending", "Closed: Valid - Remediated"

 

I thought this search should have returned the results I needed but it isn't.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

The stats command is giving you a single result for the whole search - perhaps you need to use a BY clause?

0 Karma

LionWolf
Explorer

The by clause worked! Thank you so much!

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...