Hi Team,
I have a notable event (Excessive Failed Logins on Multiple Targets) that I'm expecting to see the "dest" field. I've fleshed out asset summary and source all of the source details are populating. I'm seeing dest in other different notable events too. It's just this particular notable event. If I pull up the correlated events dest shows as a field and I can validate that values are accurate too.
Any reason why dest wouldn't be showing up in the additional fields?
Just for clarity, when the correlation search runs and produces the events/results, it should have a field 'dest' with some values. Once these events/results are written to the index=notable (can be accessed via notable macro), dest field should be there with some value, for it to appear in the Incident review screen, additional fields.
If you go to `notable` and search for your search, in the list of field values, are you seeing 'dest'?
No, "dest" for this particular search does not show under the `notable` macro. However, if I pull up the resultant set of events (Contributing Events) from the notable event, "dest" is there. Likely because it's being parsed by the data model.