To learn more, visit the Splunk documentation.

Basic Parameters

ParameterDescription
CommentA comment for the change of the notable events.
Event Filter TypeThe type of notable event selection.
Rule UIDsA list of IDs of notable events.
Search IDAn ID of a search.
StatusThe new status ID of the notable events.

Advanced Parameters

ParameterDescription
DispositionThe new disposition ID of the notable events.
New OwnerThe new owner of the notable events.
UrgencyThe new urgency of the notable events.

Example Output

{    "message": "1 event updated successfully",    "failure_count": 0,    "success": true,    "details": {},    "success_count": 1}

Workflow Library Example

Edit Notable Events with Splunk and Send Results Via Email

Preview this Workflow on desktop