Hey folks. I'm trying to write an HTML View for cases (data is coming in from Splunk). And I'm running into a problem.
If a case has a single event then the entity I might reference would look like this:
In which case the string in the "description" field of my Splunk alert is shown without issue.
However, if the case has multiple events then the string that is shown is a concatenated list of
all
of the "description" strings from every event separated by a comma.
I am looking for an entity name that
always
shows up for that data and is always just the first event.
I've seen at times. But that only seems to show up if there are multiple events (or maybe for multivalue fields?)
Are there any resources for understanding how Siemplify makes entities related to Splunk events?
Write an HTML View for cases
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.