Splunk Enterprise Security

Is it not possible to use an ampersand character in Notable Event Next Steps?

sidoyle_
Explorer

When writing plain text in the Next Steps field of a notable event such as Mitre ATT&CK it is then shown, when the notable is created, as Mitre ATT&CK which is clearly incorrect. Is it possible to escape the & character is some way ?

 

This also happens when using action:url too - [[action|url:Mitre ATT&CK ]]  is shown as Mitre ATT&CK 

Any help would be appreciated.

Labels (1)
0 Karma

marnall
Motivator

One way around this is to use a small (﹠) or fullwidth (&) ampersand.

0 Karma

sombhtr239
Explorer

Hi,

 

What do you mean by small (&)......by lowering the fonts?

0 Karma

marnall
Motivator

Not by lowering the fonts, but by using special unicode characters that look like ampersands but are not treated as ampersands. Try copying and pasting the ampersand-like characters from my post.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...