Splunk Enterprise Security

How come my fields are not showing in additional field under incident review in Splunk Enterprise Security?

saurabhsumangat
New Member

My fields are not showing in additional field under incident review in Splunk. I want to take results obtained from the query into additional fields, incident review additional field.

I have created a query using data model.

I have also renamed src_ip & dest_ip to custom name.

I am putting those custom fields into the field value provided to compress (throttling)

i am also putting the same value in asset extraction filed under notable.

but when i get the alert and open the notable from the pane, I do not see those values inside additional fields.

Could someone please help ?

0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi,

If I am understanding your question correctly, fields src_ip and dest_ip which you renamed with for example ABC and XYZ name is not displaying when you go to Incident Revivew and click on notable events under Additional Fields.

To achieve this, you need to add those renamed fields for example ABC and XYZ into ES IR configuration. Go to Enterprise Security -> Configure -> Incident Management -> Incident Review Settings, under Incident Review - Event Attributes add those new fields and after that it will display in Incident Review page.

View solution in original post

harsmarvania57
Ultra Champion

Hi,

If I am understanding your question correctly, fields src_ip and dest_ip which you renamed with for example ABC and XYZ name is not displaying when you go to Incident Revivew and click on notable events under Additional Fields.

To achieve this, you need to add those renamed fields for example ABC and XYZ into ES IR configuration. Go to Enterprise Security -> Configure -> Incident Management -> Incident Review Settings, under Incident Review - Event Attributes add those new fields and after that it will display in Incident Review page.

Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...