Splunk Enterprise Security

It is possible to group notable events in Incident Review for Splunk Enterprise Security?

HealyManTech
Explorer

I have a couple searches that trigger in Incident Review and I want to group them up by count. And than let the drill down show me the detailed information of each event. Does anyone know how to group them?

HealyManTech
Explorer

From what I been playing with. There isn't really a way to use the correlation search and stats to group information you want to seen when you expand the event, but you can have the search and group them by a count and break them down by different types. You do this by throttling with the fields to group by.

I have a feeling you can do it different but I was able to get a count of events and with the drill down see the information I wanted to see with the drill down information.

0 Karma

starcher
SplunkTrust
SplunkTrust

This is not a UI feature in ES Incident Review.

0 Karma

HealyManTech
Explorer

Not sure how this is an answer.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...