Splunk Search

Entering comments into a notable event - possible?

shiftey
Path Finder

Hi Splunk Answers,

I understand that notable events can be assigned severity as well as being assigned to different analysts.

Is it possible to update an event with comments. This would be useful so the analyst working on the event can enter useful information before assigning to another analyst.

Thanks

0 Karma

LukeMurphey
Champion

You do this by entering by editing the event and entering only a comment. Leave the other fields empty and it not change those items (will leave the status, urgency and owner unchanged).

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...