Splunk Consolidated Findings

Consolidated findings JSON payload from the Splunk investigation. Stored as a JSON string and rendered as Markdown in a dedicated layout tab via the SplunkConvertConsolidatedFindingsToMD script.

Splunk longText

Details

IDincident_splunkconsolidatedfindings
CLI Namesplunkconsolidatedfindings
TypelongText
Version-1
RequiredNo
Read OnlyNo
Use as KPINo
SearchableNo

Associated Incident Types

{
    "associatedToAll": false,
    "associatedTypes": [
        "Splunk Investigation"
    ],
    "caseInsensitive": true,
    "cliName": "splunkconsolidatedfindings",
    "closeForm": false,
    "content": true,
    "description": "Consolidated findings JSON payload from the Splunk investigation. Stored as a JSON string and rendered as Markdown in a dedicated layout tab via the SplunkConvertConsolidatedFindingsToMD script.",
    "editForm": true,
    "group": 0,
    "hidden": false,
    "id": "incident_splunkconsolidatedfindings",
    "isReadOnly": false,
    "locked": false,
    "name": "Splunk Consolidated Findings",
    "neverSetAsRequired": false,
    "ownerOnly": false,
    "propagationLabels": [
        "all"
    ],
    "required": false,
    "sla": 0,
    "system": false,
    "threshold": 72,
    "type": "longText",
    "unmapped": false,
    "unsearchable": true,
    "useAsKpi": false,
    "version": -1,
    "fromVersion": "6.0.0",
    "supportedModules": [
        "xsiam",
        "agentix"
    ]
}