Splunk Enterprise Security

How to find source and sourcetype of notable


Hi Folks,

I want find all source and sourcetype for enable notables in Splunk ES.

Please advise.



Labels (1)
Tags (2)
0 Karma


Hi, the way I understand your question is that you are looking for the configuration file with the definition of the source and the sourcetype for the events in the notable index of ES. The answer to that question is: There are none. The notable index is being populated through correlation searches that end in a ...| collect ... command that writes the result of the correlation search to the notable index. See this page for more information on how to use collect to write data to an index:  https://docs.splunk.com/Documentation/SplunkCloud/8.1.2008/SearchReference/Collect




Tags (1)
0 Karma

Splunk Employee
Splunk Employee

Did you try a search for index=notable & then see the source and sourcetype as selected fields or interesting fields in the results?  

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Updates (ESCU) - New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new content via the Enterprise ...

Thought Leaders are Validating Your Hard Work and Training Rigor

As a Splunk enthusiast and member of the Splunk Community, you are one of thousands who recognize the value of ...

.conf23 Registration is Now Open!

Time to toss the .conf-etti 🎉 —  .conf23 registration is open!   Join us in Las Vegas July 17-20 for ...