Splunk Enterprise Security

Create Investigation SOAR

Giancarlo_Pasq
New Member

Hi,

I need to create an investigation with SOAR.

When I create the investigation, it doesn't link the Finding to the Investigation. Do you have a playbook that can help me with this feature?

 

Giancarlo_Pasq_0-1754049837198.png

Giancarlo_Pasq_1-1754049866749.png

 

Giancarlo_Pasq_2-1754049874745.pngGiancarlo_Pasq_3-1754049899926.png

 

 

Labels (3)
0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Community Feedback

We Want to Hear from You! Share Your Feedback on the Splunk Community   The Splunk Community is built for you ...

Manual Instrumentation with Splunk Observability Cloud: Implementing the ...

In our observability journey so far, we've built comprehensive instrumentation for our Worms in Space ...