Splunk Enterprise Security

Enterprise Security notable events, how to calculate Alert acknowledged / Alert closed Report?? Is there any report in Splunk or please let me know the query to generate report??

IWilsonR
Engager

Enterprise Security notable events, how to calculate Alert acknowledged / Alert closed Report?? Is there any report in Splunk or please let me know the query to generate report??

0 Karma

IWilsonR
Engager

Hi All,

Anyone know how to pull the above report from splunk??

0 Karma

IWilsonR
Engager

Anyone know this, need your assistance.

0 Karma

lakshman239
Influencer

Have you looked at the Audit->Incident Review Audit dashboard? This shows reviewed/closed ones.

You can look at the underlying searches and update as needed.

You can also look at http://dev.splunk.com/view/enterprise-security/SP-CAAAFBA to view diff macros and create searches to match your need

e.g |incident_review | rename status_label AS status |

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...