Splunk Search

Splunk Enterprise Security: Is there a way to Auto-Populate the name field with a custom nomenclature?

gworkun
Explorer

Quick question about Splunk ES:

On version 4.7.4 I am curious if there was a way to do this. On Investigations, we are going to add a new Investigation Journal/Investigation. Is there a way to populate the name field with a custom nomenclature? We wanted to generate Investigation names programmatically where possible to keep things consistent, like adding the date/custom character set each time or iterate by 1 or some interval to ensure names are correct.

If there's something in a .conf file to adjust or if it's just not currently possible, any advice is helpful. Thanks!

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...