Splunk Enterprise Security
Highlighted

Is it possible to generate a "ticket number" style reference for a notable event?

New Member

I'd like each notable event that is raised in ES to have a unique "ticket number" style reference, automatically incrementing as events are raised - along the same kind of lines as ticket reference numbers that are created in systems like ServiceNow when a ticket is raised.

I appreciate that the event_id field is a unique reference for each notable but it's not user friendly enough to be used as a point of reference between multiple analysts

Is there a way to achieve what I am looking for?

0 Karma
Highlighted

Re: Is it possible to generate a "ticket number" style reference for a notable event?

Engager

You could build a lookup process, which would link the event_id to a more user-friendly ticket number. I am sure that it could be automated with a python script, or some other form of scripting.

0 Karma
Highlighted

Re: Is it possible to generate a "ticket number" style reference for a notable event?

Builder

For now, I would check out the "Share Notable Event" action in the Actions dropdown per notable event. This produces direct hyperlinks to the notable event with a copy-clipboard option. While not a "ticket number", this link can be distributed in digital-friendly ways:

https://server:8000/splunk-es/en-US/app/SplunkEnterpriseSecuritySuite/incidentreview?form.srch=ruleid%3DDB9D6F9F-4BFD-4A81-8852-39474DCB9D56%40%40notable%40%405dc87d1d390c9c47b2a7de18d2cc7bc3&earliest=1477325415&latest=1477325417

alt text