Splunk Enterprise Security

Is it not possible to use an ampersand character in Notable Event Next Steps?

sidoyle_
Explorer

When writing plain text in the Next Steps field of a notable event such as Mitre ATT&CK it is then shown, when the notable is created, as Mitre ATT&CK which is clearly incorrect. Is it possible to escape the & character is some way ?

 

This also happens when using action:url too - [[action|url:Mitre ATT&CK ]]  is shown as Mitre ATT&CK 

Any help would be appreciated.

Labels (1)
0 Karma

marnall
Motivator

One way around this is to use a small (﹠) or fullwidth (&) ampersand.

0 Karma

sombhtr239
Explorer

Hi,

 

What do you mean by small (&)......by lowering the fonts?

0 Karma

marnall
Motivator

Not by lowering the fonts, but by using special unicode characters that look like ampersands but are not treated as ampersands. Try copying and pasting the ampersand-like characters from my post.

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...