Update or edit an event in
You can edit or set several attributes of an event, also called a container, using the /set
command.
You can set or edit these attributes:
- name
- label
- owner_id
- status
- severity
- sensitivity
Use the following format to set an attribute:
/set <attribute> <value>
You can use datapaths to set attributes for multiple events at a time. See Use a datapath in .
Examples
Rename a container
/set <current name> <new name>
Set the severity of an event
/set severity high
Set the status of an event
/set status open
Add a note in | Use a datapath in |
This documentation applies to the following versions of Splunk® Phantom (Legacy): 4.8, 4.9, 4.10, 4.10.1, 4.10.2, 4.10.3, 4.10.4, 4.10.6, 4.10.7
Feedback submitted, thanks!