Splunk Enterprise Security

Tokens in notable event titles and descriptions not getting expanded to include the values of the tokens on the Incident

VasukiPramod
Explorer


Tokens in notable event titles and descriptions not getting expanded to include the values of the tokens on the Incident Review dashboard, though the search Time extractions does exists in the notable event

Example:-

My Notable Event Title Contains the following text

Suspicious activity detected from User $UserId$

Expected Output for Title in Incident Review Dashboard

Suspicious activity detected from User XYZ

How the Title Column gets displayed in Incident Review dashboard

Suspicious activity detected from User $UserId$

However, the extractions does work for built-in extractions or fields like sourcetype etc.  Tokens work with few extractions, and not with few even though both of the search time extractions does exists in the notable events

Labels (2)
0 Karma

SONY_anilyelmar
Explorer

We faced same and got fixed with ES 6.6.1 +hot fix splunk provided

0 Karma

lakshman239
Influencer

Pls ensure the underlying correlation search returns a valid value for UserId, as this will be used in the Incident review screen.

0 Karma

VasukiPramod
Explorer

Yes........... We do get valid result when we run the search (correlation search) in Splunk, only Incident Review dashboard does have challenge to expand the token values

Tags (1)
0 Karma

lakshman239
Influencer

Where in Incident Review dashboard, do you see the issue? In title, description, notable?  Generally all these should work with $fieldname$.  If its in the Incident review field values pane, then ensure the field is available as described in https://docs.splunk.com/Documentation/ES/5.0.0/Admin/Customizenotables 

Hope this helps.

0 Karma

VasukiPramod
Explorer

The issue is seen within Tilte (rule_title) and Description fields of Incident Review dashboard... the notable event does have all the data expanded properly

0 Karma

lakshman239
Influencer

What's your ES version and Splunk enterprise version.? I have n't seen this issue in ES 5.3.1, 6.x. You may also want to raise a case with support, if its only occurring on specific version.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...