Splunk Enterprise Security

Is it not possible to use an ampersand character in Notable Event Next Steps?

sidoyle_
Explorer

When writing plain text in the Next Steps field of a notable event such as Mitre ATT&CK it is then shown, when the notable is created, as Mitre ATT&CK which is clearly incorrect. Is it possible to escape the & character is some way ?

 

This also happens when using action:url too - [[action|url:Mitre ATT&CK ]]  is shown as Mitre ATT&CK 

Any help would be appreciated.

Labels (1)
0 Karma

marnall
Motivator

One way around this is to use a small (﹠) or fullwidth (&) ampersand.

0 Karma

sombhtr239
Explorer

Hi,

 

What do you mean by small (&)......by lowering the fonts?

0 Karma

marnall
Motivator

Not by lowering the fonts, but by using special unicode characters that look like ampersands but are not treated as ampersands. Try copying and pasting the ampersand-like characters from my post.

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Fall Into Learning with New Splunk Education Courses

Every month, Splunk Education releases new courses to help you branch out, strengthen your data science roots, ...

Super Optimize your Splunk Stats Searches: Unlocking the Power of tstats, TERM, and ...

By Martin Hettervik, Senior Consultant and Team Leader at Accelerate at Iver, Splunk MVPThe stats command is ...

How Splunk Observability Cloud Prevented a Major Payment Crisis in Minutes

Your bank's payment processing system is humming along during a busy afternoon, handling millions in hourly ...