Splunk Enterprise Security

I want to send the event_id of the notable event to jira service desk.

Loves-to-Learn Lots


I am trying to send the notable event to jira service desk

Data fields such as rule name are transmitted normally.

But the event_id field appears blank.

Without event_id, I can't come back to a notable event. Then no further analysis, such as investigation

How can I add an event_id or link related to the notable event in jira's ticket?

Thank you.

Labels (1)
0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!