Splunk Enterprise Security

More Enterprise Security Correlation Search Variable Substitution for Contributing Events- Is there documentation?

lugoon
Explorer

As in previous posts I am talking about using variables or tokens in the Contributing Events part of enterprise security.

 

1. When I use $host$ it substitutes the actual Splunk Host instead of the host returned from the correlation search. 

2. Can someone provide Splunk documentation links for creating or using Variables in the Drilldown search or contributing events search?

3. I am requesting and have requested in Splunk Ideas "TO MAKE THE **bleep** DRILL DOWN SEARCH WINDOW A MULTI-LINED TEXT BOX" since Splunk Enterprise Security version 6.0 and none of the GUI issues were not addressed! 

HELP ME OBI-WAN!!! 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...