Splunk Search

How do you add notes for events?

dokaas_2
Path Finder

I'm looking for a way to use a modal form to add comments to events. The behavior would be to click on an event, have a modal form displayed with a textfield box, the user adds their comments, and then posts the comments to a Splunk index.

The modal form isn't too much of a problem, I don't know how to get the information into Splunk (REST API maybe)?

0 Karma

woodcock
Esteemed Legend

Splunk's product stores this kind of thing in a KV Store collection but you could also store it into a Summary Index using | collect.

Get Updates on the Splunk Community!

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...