Splunk Enterprise Security

Splunk Enterprise Security: How can I edit a notable table in the Incident Review dashboard to alternate row colors?

tonymorin
Explorer

I want to zebra strip (gray, white, gray, white)/alternate the row colors in the triggered notable table in the Incident Review dashboard. I need help either editing or converting it to HTML so i can edit the raw code. I know the CSS to add, just need to know how or if i can edit?
alt text

Thanks in advance

0 Karma
1 Solution

jstoner_splunk
Splunk Employee
Splunk Employee

I have not played around with it in depth but the place you will want to look is in $SPLUNK_HOME/etc/apps/SA-ThreatIntelligence/appserver/static/js/components/incident_review.

There are css and js files that can be manipulated.

View solution in original post

0 Karma

jstoner_splunk
Splunk Employee
Splunk Employee

I have not played around with it in depth but the place you will want to look is in $SPLUNK_HOME/etc/apps/SA-ThreatIntelligence/appserver/static/js/components/incident_review.

There are css and js files that can be manipulated.

0 Karma

aakwah
Builder

I think that was possible at 2017 😊

Now there is an automatically generated js file here ./apps/SA-ThreatIntelligence/appserver/static/build/pages/incident_review.js 

0 Karma

tonymorin
Explorer

cool thanks I will check it out on my test server. and get back you to if i can get it to work.

0 Karma
Get Updates on the Splunk Community!

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...