Splunk Enterprise Security

How to get a notable event's drilldown URL

zyun
Explorer

We're currently using Splunk ES, and would like to grab the link to a notable event's drilldown link on the ES Incident Review page without having to manually copy it. 

The closest solution that I've come across is automatically building the URL by using a `notable` search and piecing together the earliest/latest times and drilldown search, but I feel like there might be a more elegant solution out there.

0 Karma
1 Solution

zyun
Explorer

Found that using the orig_sid in the notable's event fields can provide the indirect link to the drilldown. 

Ex. localhost:8000/en-US/app/SplunkEnterpriseSecuritySuite/search?sid=<orig_sid>

View solution in original post

0 Karma

zyun
Explorer

Found that using the orig_sid in the notable's event fields can provide the indirect link to the drilldown. 

Ex. localhost:8000/en-US/app/SplunkEnterpriseSecuritySuite/search?sid=<orig_sid>

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...