Add custom fields to add to investigation types in Splunk Enterprise Security
Add custom fields to match your business processes and identify the investigations that might require more attention.
A custom field is a unique label that you can assign to an investigation type in Splunk Enterprise Security. For example, if you want to investigate phishing incidents by tracing the emails back to their sources, you can create a custom field like originating sender and assign the phishing investigation type to it to accelerate the investigation. You can view and edit custom field values for an investigation in the Overview tab.
Create a custom field
Follow these steps to create a custom field:
- In Splunk Enterprise Security, select the Configure tab.
- Select Findings and Investigations and then select Custom fields.
- Select +Custom field to create custom fields for specific investigation types to match your business processes.'.
- Give your custom field a name.
- Decide whether you want your custom field to be global. Global custom fields apply to all investigations.
- (optional) To assign an investigation type to your custom field, select No for Global Field, and then enter the investigation type. You can either enter the name of an existing investigation type or create a new one.
- Select a data type, For example, Alpha, Alphanumeric, IP address, Numeric.
- Select a field type. If you select Selection for field type, add field values.
- Decide whether you want to allow inline editing for the custom field value. Select the Allow inline editing check box to automatically save edits made to the field value in the Overview tab of an investigation. If you deselect the check box, you can still edit the custom field value along with other summary field values.
- Select whether or not you want to require a custom field value before closing an investigation. Selecting Yes for Resolution needed requires a user to enter a value for the custom field in the Overview tab of their investigation before they can close the investigation.
- Select Confirm.
Manage custom fields
You can manage your existing custom fields in the custom fields table by deleting the ones you no longer want and by reordering the ones you do. You can also edit the properties of a custom field you already created.
The following table identifies the actions to manage custom fields:
| Action | Steps | 
|---|---|
| Delete | Select the trash can icon ( | 
| Edit | Select the pencil icon ( | 
| Reorder | Select and drag the move icon ( | 
See also
For more information on investigation types, see the product documentation: