Security

How to add splunk es adaptive response action notable event?

abi2023
Path Finder

I am try add to my notable event in correlation search next step analyst need to take. I am see some issue.

when I list next step action for analyst to take. I am getting my my next step action getting truncated in notable event in incident review page.

step 1 and step 2 are in same line even after I separate them by line.

Labels (1)
Tags (1)
0 Karma

VatsalJagani
Super Champion

@abi2023 - There may be limit of number of characters for "Next Steps" on the Incident Review page.

How long is your "Next Steps" text?

 

I hope this helps!!!

Get Updates on the Splunk Community!

Splunk Observability Cloud | Customer Survey!

If you use Splunk Observability Cloud, we invite you to share your valuable insights with us through a brief ...

Happy CX Day, Splunk Community!

Happy CX Day, Splunk Community! CX stands for Customer Experience, and today, October 3rd, is CX Day — a ...

.conf23 | Get Your Cybersecurity Defense Analyst Certification in Vegas

We’re excited to announce a new Splunk certification exam being released at .conf23! If you’re going to Las ...