- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SE-IncidentReviewDashboard- Need metrics of Notables by Investigation Options
vn_g
Path Finder
12-22-2020
09:24 PM
In Splunk Enterprise Security , Incident Review Dashboard , I am adding 2 different Investigation Option to the notables by clicking on "Add Event to Investigation".
Now , my requirement is to find out the metrics of each Invegistation Option. For example , How many notables exist with a particular investigation Option. Is it possible?
