Splunk Enterprise Security

Notable Event Tags

ErraticIncome93
Explorer

I am trying to assign custom tags to notable events so that they can be triaged by certain analysts, i.e., tier 1. I have a cron scheduled search created and it is set to create notable events; this works fine. I then setup a corresponding tag for that search_name but when I try to filter by the tag name in the tag field in the Incident Review dashboard it does not show up.

scheduled search (search name is _triage_test) that is working and generates a notable: index=snort signature="test rule"
tag (tag name is _use_case_test) that is not working: search_name=_triage_test

Any ideas? Thanks.

1 Solution

ErraticIncome93
Explorer

figured it out.... i was creating tags in the search app instead of the ES app =/

View solution in original post

0 Karma

ErraticIncome93
Explorer

figured it out.... i was creating tags in the search app instead of the ES app =/

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If your problem is solved, please accept the answer.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...

Join the Final Session of the Data Management & Federation Bootcamp Series

Over the past three sessions of the Data Management & Federation Bootcamp Series, we've explored how to build ...

From Data to Insight: Announcing the Winners of the Splunk Dashboard Contest

Hi Splunkers, First off, thank you to everyone who participated in our very first From Data to Insight: The ...