QuestionQ30

Creating Correlation Searches

When you create custom correlation searches, which format is used to embed field values in a notable event’s title, description, and drill-down fields?

  • A $fieldname$
  • B ג€fieldnameג€
  • C %fieldname%
  • D fieldname
Explanation

Splunk Enterprise Security correlation searches use dollar-sign token substitution for notable-event content and drill-down fields. A token such as $src$ is replaced with the corresponding field value when the notable event is generated.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!