Splunk Enterprise Security

How do I modify the raw data location in Enterprise Security alert output?

donaldmayo
New Member

Hello All!

I'm currently in the process of going over our correlation rules and outputs. I've reached a point in Enterprise Security that when an alert is sent out on a triggered correlation rule it sends out the Incident Response steps. Is there a way to move the data that triggered the event to the top of the email that's sent out? I've provided a screenshot that shows the event data, which is at the end of the email, after the Incident Response steps, rather than at the top.

alt text

Thank you!
Oliver

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...