Splunk Enterprise Security

Splunk Enterprise Security update multiple notables at the same time using REST API

muradgh
Path Finder

Hi all!

I have been trying to automate a task lately,

So I'm able to edit one notable event using the API just fine, but I want to edit multiple notables at the same time, it will be a tedious job to manually go throw each notable event and take the "event_id" one by one!

is there a way to make this happened? 

I don't know something like selecting the notable events I want to edit from the Enterprise Security incident review page and copy their "event_ip" to a clipboard or something like this?

Thanks in advance.

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...