Splunk Enterprise Security

Splunk Enterprise Security update multiple notables at the same time using REST API

muradgh
Path Finder

Hi all!

I have been trying to automate a task lately,

So I'm able to edit one notable event using the API just fine, but I want to edit multiple notables at the same time, it will be a tedious job to manually go throw each notable event and take the "event_id" one by one!

is there a way to make this happened? 

I don't know something like selecting the notable events I want to edit from the Enterprise Security incident review page and copy their "event_ip" to a clipboard or something like this?

Thanks in advance.

Labels (2)
0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...