Splunk Enterprise Security

How to track on ES the timestamp whenever I changed in the investigations section the status of any investigation

jogonz20
Explorer

I am trying to figure out how I can track the timestamp whenever I changed the status of any recently opened investigation so that I can have the control of that, I have checked the ES audit section, specifically the Investigation Overview but there is anything similar to this.

I also checked the _audit index but not sure if the investigation roles are tracked there which in turn would be a really good option to observe.

Thanks

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

IIRC, investigations are stored in the KV Store.

---
If this reply helps you, Karma would be appreciated.
0 Karma

jogonz20
Explorer

Hello @richgalloway,

Thanks so much for replying back,

Well I checked that information but there is no record to track whenever I change the status in the investigation feature.

I was thinking that maybe with the audit index but I will need to look it closely.

Thanks,

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...