Security

How to add splunk es adaptive response action notable event?

abi2023
Path Finder

I am try add to my notable event in correlation search next step analyst need to take. I am see some issue.

when I list next step action for analyst to take. I am getting my my next step action getting truncated in notable event in incident review page.

step 1 and step 2 are in same line even after I separate them by line.

Tags (1)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@abi2023 - There may be limit of number of characters for "Next Steps" on the Incident Review page.

How long is your "Next Steps" text?

 

I hope this helps!!!

Get Updates on the Splunk Community!

Machine Learning - Assisted Adaptive Thresholding

Let’s talk thresholding. Have you set up static thresholds? Tired of static thresholds triggering false ...

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...