Dear All,
We have to include the urgency of the event in the Splunk App for Enterprise Security notable events. Could anybody help me out which variable I need to add in the subject line?
$alert.severity$
is taking the severity level. it's not idle variable we can use it.
Thanks,
Sunil
$urgency$
This worked for me in the Title of the Notable Event (in the Correlation Search), and should work in the Email Subject as well, I'd tend to believe.