Splunk Enterprise Security

I see 5 Additional fields in one notable event and 10 additioinal fields in another notable event under incident review. Can I configure the additional fields that can be displayed?

ksncksnc
Engager
 

martin_mueller
SplunkTrust
SplunkTrust

Different correlation searches produce different notable event fields, even the same correlation search may not produce every field every time.

To change that behaviour you can change the corresponding correlation search.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...