Hello,
I am running into an issue with passing the rule_title value from Splunk to Resilient. Normally the rule_title is pulled from the notable event, however I am adding a dynamic field to the notable event (within Splunk) which comes over to resilient as "searchCommand".
For example the rule_title for the notable event would be: Threat - Malicious Download - test.exe
where test.exe is being dynamically populated through the notable event action with the below syntax:
Threat - Malicious Download - $file_name$.
In resilient this looks like: Threat - Malicious Download - searchCommand
Is there any way to pass the rule_title from a notable event to resilient with a dynamic value/field?
------------------------------
Alexander Lombardi
------------------------------