<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Way to search ES Investigations for artifact or IOC? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Way-to-search-ES-Investigations-for-artifact-or-IOC/m-p/541427#M9738</link>
    <description>&lt;P&gt;Are you referring to these notes?&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/ES/6.4.1/User/Addtoaninvestigation#Add_a_note_to_an_investigation" target="_blank"&gt;https://docs.splunk.com/Documentation/ES/6.4.1/User/Addtoaninvestigation#Add_a_note_to_an_investigation&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I don't think there's a way to search for content within the notes, but only to search for the name/title of the notes. That sounds like a good idea though. Perhaps submit it to&amp;nbsp;&lt;A href="https://ideas.splunk.com/" target="_blank"&gt;https://ideas.splunk.com/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 25 Feb 2021 21:55:27 GMT</pubDate>
    <dc:creator>lkutch_splunk</dc:creator>
    <dc:date>2021-02-25T21:55:27Z</dc:date>
    <item>
      <title>Way to search ES Investigations for artifact or IOC?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Way-to-search-ES-Investigations-for-artifact-or-IOC/m-p/538837#M9684</link>
      <description>&lt;P&gt;Is there a way to search all ES Investigations for a specific artifact or IOC that may be documented in the notes?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 21:48:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Way-to-search-ES-Investigations-for-artifact-or-IOC/m-p/538837#M9684</guid>
      <dc:creator>ch1221</dc:creator>
      <dc:date>2021-02-05T21:48:52Z</dc:date>
    </item>
    <item>
      <title>Re: Way to search ES Investigations for artifact or IOC?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Way-to-search-ES-Investigations-for-artifact-or-IOC/m-p/541427#M9738</link>
      <description>&lt;P&gt;Are you referring to these notes?&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/ES/6.4.1/User/Addtoaninvestigation#Add_a_note_to_an_investigation" target="_blank"&gt;https://docs.splunk.com/Documentation/ES/6.4.1/User/Addtoaninvestigation#Add_a_note_to_an_investigation&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I don't think there's a way to search for content within the notes, but only to search for the name/title of the notes. That sounds like a good idea though. Perhaps submit it to&amp;nbsp;&lt;A href="https://ideas.splunk.com/" target="_blank"&gt;https://ideas.splunk.com/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 21:55:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Way-to-search-ES-Investigations-for-artifact-or-IOC/m-p/541427#M9738</guid>
      <dc:creator>lkutch_splunk</dc:creator>
      <dc:date>2021-02-25T21:55:27Z</dc:date>
    </item>
    <item>
      <title>Re: Way to search ES Investigations for artifact or IOC?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Way-to-search-ES-Investigations-for-artifact-or-IOC/m-p/541518#M9741</link>
      <description>&lt;P&gt;Yes, those notes or any threat detection in a notable associated to an investigation would be useful.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2021 14:34:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Way-to-search-ES-Investigations-for-artifact-or-IOC/m-p/541518#M9741</guid>
      <dc:creator>ch1221</dc:creator>
      <dc:date>2021-02-26T14:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: Way to search ES Investigations for artifact or IOC?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Way-to-search-ES-Investigations-for-artifact-or-IOC/m-p/541522#M9742</link>
      <description>&lt;P&gt;Added as an Idea.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2021 14:38:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Way-to-search-ES-Investigations-for-artifact-or-IOC/m-p/541522#M9742</guid>
      <dc:creator>ch1221</dc:creator>
      <dc:date>2021-02-26T14:38:26Z</dc:date>
    </item>
  </channel>
</rss>

