Splunk Enterprise Security

Is it not possible to use an ampersand character in Notable Event Next Steps?

sidoyle_
Explorer

When writing plain text in the Next Steps field of a notable event such as Mitre ATT&CK it is then shown, when the notable is created, as Mitre ATT&CK which is clearly incorrect. Is it possible to escape the & character is some way ?

 

This also happens when using action:url too - [[action|url:Mitre ATT&CK ]]  is shown as Mitre ATT&CK 

Any help would be appreciated.

Labels (1)
0 Karma

marnall
Motivator

One way around this is to use a small (﹠) or fullwidth (&) ampersand.

0 Karma

sombhtr239
Explorer

Hi,

 

What do you mean by small (&)......by lowering the fonts?

0 Karma

marnall
Motivator

Not by lowering the fonts, but by using special unicode characters that look like ampersands but are not treated as ampersands. Try copying and pasting the ampersand-like characters from my post.

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Building Momentum: Splunk Developer Program at .conf25

At Splunk, developers are at the heart of innovation. That’s why this year at .conf25, we officially launched ...