Is there a way to automatically escalate a finding (or set of findings) to an investigation in Splunk Enterprise Security Mission Control, either via alert action or a API calls?
Hi @alatif113
Have you seen the Mission Control API docs? https://docs.splunk.com/DocumentationStatic/MC/Current/SplunkPlaybookAPI/#tag/Mission-Control/operat...
The create_incident endpoint in here might help you achieve this.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing