Splunk Enterprise Security

Recover Description of notable via search?

johnny_goya
Explorer

Hi everyone,

I'm trying to create a search that i can display the notable information. But i have a problema, when i display de rule_description, the field value apears with tokens. how can i recover the description with the token value?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust
0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...