Splunk Enterprise Security

Is there a way to add entire roles as collaborators to an investigation rather than just one at a time?

jadamsplunk
Path Finder

Hi all,

I'm using ES 4.7.3 and as far as I know there is only the option to add collaborators one at a time to an investigation. This doesn't work well with our existing structure of incident response (cases are not assigned to users, but the group and users take incidents from the list of active ones).

The logistics involved in adding every user to every investigation is pretty time consuming, I'm hoping there is a basic functionality to add batches of collaborators to investigations.

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...