Splunk Enterprise Security

Displaying an investigation on the Incident Review Dashboard

adnankhan5133
Communicator

If I decided to create an Investigation in Splunk ES via the Investigation Workbench from the Investigations page ("Create new Investigation"), could I also create a new notable event associated to that Investigation?

I'm trying to see if there is a way to display an investigation on the Incident Review dashboard since we are leveraging that dashboard for reporting purposes.

Labels (2)
0 Karma

lkutch_splunk
Splunk Employee
Splunk Employee

Yes, you can do that. You can start an investigation & then you can manually create a notable event called "started an investigation" (or whatever you like): 

https://docs.splunk.com/Documentation/ES/6.4.0/Admin/Createnotablesmanually#Create_a_notable_event_f...

& you can see it in Incident Review & add it to your investigation. 

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...