Splunk Enterprise Security

Help creating a table that shows specific notable information

LionWolf
Explorer

Hello Community,

 

I'm working on a search for a dashboard panel and I need some help.

I'm looking to get the owner, search_name, status_label, and the last comment.

The search I have so far is below:


`notable`
| where owner =="User1" OR owner=="User2" OR owner=="User3" OR owner=="User4" OR owner=="User5" OR owner=="User6"
| where status_label=="Ready for Review" OR status_label=="Closed: False Positive" OR status_label=="Pending" OR status_label=="Closed: Valid - Remediated"
| stats earliest(owner) AS Analyst, earliest(search_name) AS "Alert Name", latest(status_label) AS Status, latest(comment) AS Summary

Labels (1)
Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

The stats command is giving you a single result for the whole search - perhaps you need to use a BY clause?

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

In what way does this not give you what you have asked for?

0 Karma

LionWolf
Explorer

Hello ITWhisperer,

I only get one notable event, even for 30 days. I need all of the notable events that have been worked on, and that currently have the status_label of "Ready for Review", "Closed: False Positive", "Pending", "Closed: Valid - Remediated"

 

I thought this search should have returned the results I needed but it isn't.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

The stats command is giving you a single result for the whole search - perhaps you need to use a BY clause?

0 Karma

LionWolf
Explorer

The by clause worked! Thank you so much!

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...