Splunk Enterprise Security

How can we add extra Table attributes in incident review?

renjujacob88
Path Finder

Hi ,

Is it possible to add extra field just say( serial Number ) to the table attribute of the incident review? I just need the serial number on every events that it generate, just a way to track the event with serial number

alt text

Any help will be appreciated.

0 Karma

thambisetty
SplunkTrust
SplunkTrust

Hi renjujacob,

This is very late but may be this could help others.

you can add new attribute by clicking on more in

Configure > Incident Management > Incident Review Settings. as shown below .

and click on insert above then will popup window for new field to be added provide label and field value and then you can move the field where ever you want.

alt text

————————————
If this helps, give a like below.
0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...