Splunk Enterprise Security

How do you tag a user with watchlist in Splunk Enterprise Security?


If I have a notable event is there a way within incident review to tag the user with watchlist?

0 Karma


Under the Example methods of adding asset and identity data in Splunk Enterprise Security you could refer to perform the steps under Manually add new asset or identity data, or you could update your identity lookup to set the required flag...

0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!