Connectors
...
Actions
Edit Notable Event
5 min
description update details of existing notable events in cisco splunk using the provided data body endpoint url services/notable update method post inputs data body (object) – required ruleuids (array) – required searchid (string) newowner (string) urgency (string) status (string) comment (string) disposition (string) an id for a disposition that matches a disposition in the reviewstatuses conf configuration file required only if you are changing the disposition of the event output example \[ { "status code" 200, "response headers" { "date" "mon, 17 jul 2023 20 53 02 gmt", "expires" "thu, 26 oct 1978 00 00 00 gmt", "cache control" "no store, no cache, must revalidate, max age=0", "content type" "application/json; charset=utf 8", "x content type options" "nosniff", "transfer encoding" "chunked", "content encoding" "gzip", "vary" "accept encoding, cookie, authorization", "connection" "keep alive", "x frame options" "sameorigin", "server" "splunkd" }, "reason" "ok", "json body" { "message" "", "failure count" 0, "success" true, "success count" 2 } } ] output parameters status code (number) reason (string) json body (object) message (string) failure count (number) success (boolean) success count (number) response headers header type date string expires string cache control string content type string x content type options string transfer encoding string content encoding string vary string connection string x frame options string server string