I want to add a new Security Domain called "Email" in Enterprise Security (ES) App and later map it to notables. Right now "Threat", "Network", "Identity" are among a few that are available. Is there a way to achieve this ?
yes, you can modify the lookup that is responsible for the available Security Domains (which is also the name of the lookup). Take a look here for an overview of the internal ES lookups: https://docs.splunk.com/Documentation/ES/5.3.1/Admin/Manageinternallookups
View solution in original post