- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Issue with event_id Not Appearing When Sending Events from Splunk ES to SOAR
kn450
Engager
01-15-2025
04:58 AM
Description:
Hello,
I am experiencing an issue with the "event_id" field when transferring notable events from Splunk Enterprise Security (ES) to Splunk SOAR.
Details:
- When sending the event to SOAR using an Adaptive Response Action (Send to SOAR), the event is sent successfully, but the "event_id" field does not appear in the data received in SOAR.
Any assistance or guidance to resolve this issue would be greatly appreciated.
Thank you
