Splunk Enterprise Security

I want to send the event_id of the notable event to jira service desk.

linearity_abcd
Loves-to-Learn Lots

Hello

I am trying to send the notable event to jira service desk

Data fields such as rule name are transmitted normally.

But the event_id field appears blank.

Without event_id, I can't come back to a notable event. Then no further analysis, such as investigation

How can I add an event_id or link related to the notable event in jira's ticket?

Thank you.

Labels (1)
0 Karma

alexeyglukhov
Path Finder

hi, did you end up with something viable ?

thanks

0 Karma

linearity_abcd
Loves-to-Learn Lots

Hello,

 

I’m not sure how it works in the latest version of the add-on,

but at that time, it was correct that the event_id was not passed.

 

I wrote my query by referring to the notable macro.

By generating the event_id using eval and passing it as a custom field,

it was possible to send it over.

 

Thank you.

 

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...