We have multiples lines of text in our detailed Splunk ES notable event descriptions. In order to make the text readable by our operations team, we want to manually force a newline when appropriate.
Below are a few sets of newline options we have tried that do not work.
Any ideas? Also note that I need to be able to change this through the edit correlation search GUI and not manual file end from the console command line.
\n
</p>
\<\/p\>
<\p>
[p]
http://docs.splunk.com/Documentation/ES/4.6.0/User/IncludedResponseActions#Create_a_notable_event
See item 5
This question seems pretty popular. I would open a support request provide examples of what you are trying to do and why.
The more examples / use cases and customer cases we have the more visible / valid the enhancement becomes.
This was a topic today in our internal chat. Let me know the case number if you do.
Still needing this.
Did you ever find a solution to this?
No solution so far.