Splunk Enterprise Security

'Next Steps' Variable Substitution in Splunk Enterprise Security

New Member

Hello all!


I am attempting to dynamically add 'Next Steps' to a notable event based off a lookup table in my Correlation Search Splunk Query. I was wondering if it is possible to do this using Variable Substitution? 


For example if my notable name is X, then populate the 'Description' and 'Next Steps' columns with the associated  fields in the lookup table.


If this is not possible at the moment, can anyone suggest another way that I could get this data to dynamically populate?



Labels (3)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...