Splunk Enterprise Security

How can we search the notables using short id as filter in incident dashboard on Splunk ES?

abhijitnath89
Path Finder

Hi All,

I am using Splunk ES. We create short Ids for notables.

How can we search the notables using short id as filter in incident dashboard on Splunk ES.

Labels (1)
0 Karma

johnvdzon
Explorer

Within the ES app.
Select "Incident Review" 
Look for the filter "Time or Associations",  select Associations
A new filter option will appear. "Short ID" 
Move 1 filter to the right with the name "Select". If you select this one, you can enter or select the Short ID you are looking for.

 

 

KKuser
Path Finder

The method you are saying works for Splunk Enterprise version 7.2.0 and lower. The short ID filter is not available by default once you upgrade to Splunk Enterprise Security version 7.3.0. 

Follow the steps for reference: https://docs.splunk.com/Documentation/ES/7.3.0/Admin/CustomizeIR#Create_a_short_ID_column_to_filter_...

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...