Splunk Enterprise Security

Splunk Enterprise Security: Is there a way manually force a newline in notable event descriptions?


We have multiples lines of text in our detailed Splunk ES notable event descriptions. In order to make the text readable by our operations team, we want to manually force a newline when appropriate.

Below are a few sets of newline options we have tried that do not work.

Any ideas? Also note that I need to be able to change this through the edit correlation search GUI and not manual file end from the console command line.


Splunk Employee
Splunk Employee


See item 5

This question seems pretty popular. I would open a support request provide examples of what you are trying to do and why.

The more examples / use cases and customer cases we have the more visible / valid the enhancement becomes.

This was a topic today in our internal chat. Let me know the case number if you do.


Still needing this.

0 Karma


Did you ever find a solution to this?

0 Karma


No solution so far.

0 Karma
Get Updates on the Splunk Community!

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...

Cloud Platform | Migrating your Splunk Cloud deployment to Python 3.7

Python 2.7, the last release of Python 2, reached End of Life back on January 1, 2020. As part of our larger ...