<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Enterprise Security: If an analyst added a notable event to an investigation, how does another analyst open that notable event to review it? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-If-an-analyst-added-a-notable-event/m-p/248461#M1754</link>
    <description>&lt;P&gt;I believe this was fixed in updates to ES. &lt;/P&gt;</description>
    <pubDate>Sun, 26 Feb 2017 14:48:56 GMT</pubDate>
    <dc:creator>panovattack</dc:creator>
    <dc:date>2017-02-26T14:48:56Z</dc:date>
    <item>
      <title>Splunk Enterprise Security: If an analyst added a notable event to an investigation, how does another analyst open that notable event to review it?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-If-an-analyst-added-a-notable-event/m-p/248457#M1750</link>
      <description>&lt;P&gt;If an analyst has added a notable event to an investigation, how does another analyst open that notable event to review it? There does not seem to be an option to view the raw event referenced in the timeline or jump to the all the notable events for an investigation.  The same goes for Splunk Events. &lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2016 20:07:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-If-an-analyst-added-a-notable-event/m-p/248457#M1750</guid>
      <dc:creator>panovattack</dc:creator>
      <dc:date>2016-01-26T20:07:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: If an analyst added a notable event to an investigation, how does another analyst open that notable event to review it?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-If-an-analyst-added-a-notable-event/m-p/248458#M1751</link>
      <description>&lt;P&gt;Have you tried going to Actions, Show Source for the Notable Event?  Below is a screenshot from my system:&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/993iC6C714832C0D5BBC/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2016 18:06:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-If-an-analyst-added-a-notable-event/m-p/248458#M1751</guid>
      <dc:creator>AndySplunks</dc:creator>
      <dc:date>2016-01-27T18:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: If an analyst added a notable event to an investigation, how does another analyst open that notable event to review it?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-If-an-analyst-added-a-notable-event/m-p/248459#M1752</link>
      <description>&lt;P&gt;There is no way to do that in the latest version, unfortunately. You can view only notable events or splunk events on an investigation by filtering on a &lt;STRONG&gt;type:&lt;/STRONG&gt; of notable event or splunk event. &lt;/P&gt;

&lt;P&gt;In the latest release, however, there is no way to click through to the raw events from the investigation timeline. &lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2016 23:44:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-If-an-analyst-added-a-notable-event/m-p/248459#M1752</guid>
      <dc:creator>smoir_splunk</dc:creator>
      <dc:date>2016-02-03T23:44:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: If an analyst added a notable event to an investigation, how does another analyst open that notable event to review it?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-If-an-analyst-added-a-notable-event/m-p/248460#M1753</link>
      <description>&lt;P&gt;@panovattack I wanted to follow up on my answer and let you know that in ES 4.1 you can do this! When you add a notable event there is also a link to view the notable event on incident review. &lt;span class="lia-inline-image-display-wrapper" image-alt="notable event on an investigation timeline showing the information on notable events and a link to view the notable event on incident review"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/994iA34AF5D36891016C/image-size/large?v=v2&amp;amp;px=999" role="button" title="notable event on an investigation timeline showing the information on notable events and a link to view the notable event on incident review" alt="notable event on an investigation timeline showing the information on notable events and a link to view the notable event on incident review" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2016 17:08:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-If-an-analyst-added-a-notable-event/m-p/248460#M1753</guid>
      <dc:creator>smoir_splunk</dc:creator>
      <dc:date>2016-04-06T17:08:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: If an analyst added a notable event to an investigation, how does another analyst open that notable event to review it?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-If-an-analyst-added-a-notable-event/m-p/248461#M1754</link>
      <description>&lt;P&gt;I believe this was fixed in updates to ES. &lt;/P&gt;</description>
      <pubDate>Sun, 26 Feb 2017 14:48:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-If-an-analyst-added-a-notable-event/m-p/248461#M1754</guid>
      <dc:creator>panovattack</dc:creator>
      <dc:date>2017-02-26T14:48:56Z</dc:date>
    </item>
  </channel>
</rss>

