Splunk Enterprise Security

I want to send the event_id of the notable event to jira service desk.

linearity_abcd
Loves-to-Learn Lots

Hello

I am trying to send the notable event to jira service desk

Data fields such as rule name are transmitted normally.

But the event_id field appears blank.

Without event_id, I can't come back to a notable event. Then no further analysis, such as investigation

How can I add an event_id or link related to the notable event in jira's ticket?

Thank you.

Labels (1)
0 Karma

alexeyglukhov
Path Finder

hi, did you end up with something viable ?

thanks

0 Karma

linearity_abcd
Loves-to-Learn Lots

Hello,

 

I’m not sure how it works in the latest version of the add-on,

but at that time, it was correct that the event_id was not passed.

 

I wrote my query by referring to the notable macro.

By generating the event_id using eval and passing it as a custom field,

it was possible to send it over.

 

Thank you.

 

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...