Listing incident review and the closing comments

index=_audit sourcetype="incident_review"
| table rule_name comment status
| rename rule_name as "Notable Event" comment as "Closing Comment" status as Status
| eval Status=if(Status=5,"Closed",if(Status=2,"In Progress","Not assigned"))
| dedup "Closing Comment"
Share This:
Tagged:

Leave A Comment?