Splunk Enterprise Security

I want to send the event_id of the notable event to jira service desk.

linearity_abcd
Loves-to-Learn Lots

Hello

I am trying to send the notable event to jira service desk

Data fields such as rule name are transmitted normally.

But the event_id field appears blank.

Without event_id, I can't come back to a notable event. Then no further analysis, such as investigation

How can I add an event_id or link related to the notable event in jira's ticket?

Thank you.

Labels (1)
0 Karma

alexeyglukhov
Path Finder

hi, did you end up with something viable ?

thanks

0 Karma

linearity_abcd
Loves-to-Learn Lots

Hello,

 

I’m not sure how it works in the latest version of the add-on,

but at that time, it was correct that the event_id was not passed.

 

I wrote my query by referring to the notable macro.

By generating the event_id using eval and passing it as a custom field,

it was possible to send it over.

 

Thank you.

 

0 Karma
Get Updates on the Splunk Community!

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

Unlock Instant Security Insights from Amazon S3 with Splunk Cloud — Try Federated ...

Availability: Must be on Splunk Cloud Platform version 10.1.2507.x to view the free trial banner. If you are ...