Splunk Enterprise Security

Recover Description of notable via search?

Explorer

Hi everyone,

I'm trying to create a search that i can display the notable information. But i have a problema, when i display de rule_description, the field value apears with tokens. how can i recover the description with the token value?

0 Karma

SplunkTrust
SplunkTrust
0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!