Splunk Search

Splunk Enterprise Security: Is there a way to Auto-Populate the name field with a custom nomenclature?

gworkun
Explorer

Quick question about Splunk ES:

On version 4.7.4 I am curious if there was a way to do this. On Investigations, we are going to add a new Investigation Journal/Investigation. Is there a way to populate the name field with a custom nomenclature? We wanted to generate Investigation names programmatically where possible to keep things consistent, like adding the date/custom character set each time or iterate by 1 or some interval to ensure names are correct.

If there's something in a .conf file to adjust or if it's just not currently possible, any advice is helpful. Thanks!

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...