- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk Enterprise Security - How to use the Incident Review event page
Tightech
New Member
07-25-2018
09:09 AM
I have an incident which reads - "Activity from Expired User Identity" CRITICAL
Please can someone work me through how to investigate and resolve this incident.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

ChrisG

Splunk Employee
07-25-2018
09:59 AM
Have you already followed the instructions in Investigate a notable event on Incident Review in Splunk Enterprise Security and Take action on a notable event on Incident Review in Splunk Enterprise Security in the Use Splunk Enterprise Security manual?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Tightech
New Member
07-26-2018
05:56 AM
Thanks ChrisG for the response, I'll review these docs.
