Splunk Enterprise Security

Splunk Enterprise Security: Is there a way manually force a newline in notable event descriptions?

alandeandrea
Explorer

We have multiples lines of text in our detailed Splunk ES notable event descriptions. In order to make the text readable by our operations team, we want to manually force a newline when appropriate.

Below are a few sets of newline options we have tried that do not work.

Any ideas? Also note that I need to be able to change this through the edit correlation search GUI and not manual file end from the console command line.

\n
</p>
\<\/p\>
<\p>
[p]

jwelch_splunk
Splunk Employee
Splunk Employee

http://docs.splunk.com/Documentation/ES/4.6.0/User/IncludedResponseActions#Create_a_notable_event

See item 5

This question seems pretty popular. I would open a support request provide examples of what you are trying to do and why.

The more examples / use cases and customer cases we have the more visible / valid the enhancement becomes.

This was a topic today in our internal chat. Let me know the case number if you do.

jsven7
Communicator

Still needing this.

0 Karma

AndySplunks
Communicator

Did you ever find a solution to this?

0 Karma

alandeandrea
Explorer

No solution so far.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...