Splunk Enterprise Security
Highlighted

Adding an ID number to ES investigations

Communicator

Is there a way to automagically add a unique ID number to each investigation that is opened?

0 Karma
Highlighted

Re: Adding an ID number to ES investigations

SplunkTrust
SplunkTrust

don't think there is any way to add a unique number. However, there is an 'event_id' field autogenerated which is unique and ties up back to Incident Review.

0 Karma
Highlighted

Re: Adding an ID number to ES investigations

Splunk Employee
Splunk Employee

Each investigation has an id which can be found in the URL while on the investigation page:
ess_investigation?id=5c390c8abbd7066a1b17a941

0 Karma