Splunk Enterprise Security

How to find source and sourcetype of notable

DawoodKhanUlex
Engager

Hi Folks,

I want find all source and sourcetype for enable notables in Splunk ES.

Please advise.

Regards,

D

Labels (1)
Tags (2)
0 Karma

ololdach
Builder

Hi, the way I understand your question is that you are looking for the configuration file with the definition of the source and the sourcetype for the events in the notable index of ES. The answer to that question is: There are none. The notable index is being populated through correlation searches that end in a ...| collect ... command that writes the result of the correlation search to the notable index. See this page for more information on how to use collect to write data to an index:  https://docs.splunk.com/Documentation/SplunkCloud/8.1.2008/SearchReference/Collect

Cheers

Oliver

 

Tags (1)
0 Karma

lkutch_splunk
Splunk Employee
Splunk Employee

Did you try a search for index=notable & then see the source and sourcetype as selected fields or interesting fields in the results?  

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...