Splunk Enterprise Security

How do you tag a user with watchlist in Splunk Enterprise Security?

rbacker527
Engager

If I have a notable event is there a way within incident review to tag the user with watchlist?

0 Karma

gjanders
SplunkTrust
SplunkTrust

Under the Example methods of adding asset and identity data in Splunk Enterprise Security you could refer to perform the steps under Manually add new asset or identity data, or you could update your identity lookup to set the required flag...

0 Karma
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...