Splunk Enterprise Security

Audit trail for investigations

efika
Communicator

An analyst adds a note to investigation. Another analyst from another shift delete this note.
where is the audit trail that allows me to see when and who did what in an investigation ?

According to the doc :

"Investigation details from investigations created in versions earlier than 4.6.0 of Splunk Enterprise Security are stored in two KV Store collections, investigative_canvas and investigative_canvas_entries. Those collections are preserved in version 4.6.0 but the contents are added to the new investigation KV Store collections. So to restore, you may need to restore investigationinvestigation_attachmentinvestigation_eventinvestigation_leadinvestigative_canvas, and investigative_canvas_leads."

But except for the investigation KV store (| rest /services/storage/investigation/investigation) I can't access the other KV store .

Is it a missing functionality ?

 

Thanks !

 

 

 

Labels (1)
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...