Splunk Enterprise Security

How to track on ES the timestamp whenever I changed in the investigations section the status of any investigation

jogonz20
Explorer

I am trying to figure out how I can track the timestamp whenever I changed the status of any recently opened investigation so that I can have the control of that, I have checked the ES audit section, specifically the Investigation Overview but there is anything similar to this.

I also checked the _audit index but not sure if the investigation roles are tracked there which in turn would be a really good option to observe.

Thanks

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

IIRC, investigations are stored in the KV Store.

---
If this reply helps you, Karma would be appreciated.
0 Karma

jogonz20
Explorer

Hello @richgalloway,

Thanks so much for replying back,

Well I checked that information but there is no record to track whenever I change the status in the investigation feature.

I was thinking that maybe with the audit index but I will need to look it closely.

Thanks,

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...