- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk App for Enterprise Security: How to add the urgency of notable events in the email subject line?
ssuresh
Explorer
04-22-2015
12:57 AM
Dear All,
We have to include the urgency of the event in the Splunk App for Enterprise Security notable events. Could anybody help me out which variable I need to add in the subject line?
$alert.severity$
is taking the severity level. it's not idle variable we can use it.
Thanks,
Sunil
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
mparks11
Path Finder
08-31-2016
04:00 PM
$urgency$
This worked for me in the Title of the Notable Event (in the Correlation Search), and should work in the Email Subject as well, I'd tend to believe.
