Getting Data In

Splunk Enterprise security Filters

Nawab
Path Finder

I have installed the latest splunk with Splunk enterprise security on it.

I have worked with enterprise security before, and there were some filters available to filter incidents, now in this version 7.3.0 there are no filters, 

 

Is there anything wrong I am doing?

Nawab_0-1707893721812.pngNawab_1-1707893820624.png

 

Labels (1)
0 Karma
1 Solution

bharathkumarnec
Contributor

@Nawab , Please try below : https://docs.splunk.com/Documentation/ES/7.3.0/Admin/CustomizeIR

In the Splunk Enterprise Security app, select Configure.

Select General and then select General Settings.

Go to Enhanced Incident Review workflow panel.

Select Turn off.

View solution in original post

bharathkumarnec
Contributor

@Nawab , Please try below : https://docs.splunk.com/Documentation/ES/7.3.0/Admin/CustomizeIR

In the Splunk Enterprise Security app, select Configure.

Select General and then select General Settings.

Go to Enhanced Incident Review workflow panel.

Select Turn off.

splunkreal
Motivator

Hello, thanks for solution, so "enhanced" view removes those useful filters, strange...

* If this helps, please upvote or accept solution 🙂 *
0 Karma

bharathkumarnec
Contributor

@splunkreal , the filters are still there but at each individual column level, you can use those to apply filters.

0 Karma

Nawab
Path Finder

this works fro me

gcusello
SplunkTrust
SplunkTrust

Hi @Nawab ,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated by all the contributors 😉

0 Karma

Nawab
Path Finder

Yes, i am talking about the incident review dashboard of version 7.3.0, and I tried clicking it multiple times, still same. Also opened a case with splunk support

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Nawab,

I have only 7.2 version, but this issue is really strange because I don't think that Splunk remoived filters from this dashboard.

I suppose that the Splunk Support should help you.

Ciao.

Giuseppe

0 Karma

Nawab
Path Finder

yes the dashboard of enterprise security and its filters

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Nawab,

in Enterprise Security there are many dashboards:

the filters you shared seem to be the ones in the Incident Review dashboard.

Did you tried to click two times the Hide Filters button?

Ciao.

Giuseppe

0 Karma

Nawab
Path Finder

Nawab_0-1707893937398.png

These are options i want

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Nawab,

which dashboard are you speaking of?

in the Incident Review dashboard, the filters are the ones you shared.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...