Splunk Enterprise Security

How to track on ES the timestamp whenever I changed in the investigations section the status of any investigation

jogonz20
Explorer

I am trying to figure out how I can track the timestamp whenever I changed the status of any recently opened investigation so that I can have the control of that, I have checked the ES audit section, specifically the Investigation Overview but there is anything similar to this.

I also checked the _audit index but not sure if the investigation roles are tracked there which in turn would be a really good option to observe.

Thanks

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

IIRC, investigations are stored in the KV Store.

---
If this reply helps you, Karma would be appreciated.
0 Karma

jogonz20
Explorer

Hello @richgalloway,

Thanks so much for replying back,

Well I checked that information but there is no record to track whenever I change the status in the investigation feature.

I was thinking that maybe with the audit index but I will need to look it closely.

Thanks,

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...