Splunk Enterprise Security

Splunk Enterprise Security - How to use the Incident Review event page

Tightech
New Member

I have an incident which reads - "Activity from Expired User Identity" CRITICAL
Please can someone work me through how to investigate and resolve this incident.

0 Karma

ChrisG
Splunk Employee
Splunk Employee
0 Karma

Tightech
New Member

Thanks ChrisG for the response, I'll review these docs.

0 Karma
Get Updates on the Splunk Community!

Join the Splunk Developer Program Hackathon: Splunk Build-a-thon!

The Splunk Developer Program is launching in beta, and we’re celebrating with an exciting hackathon! This is ...

Announcing the Expansion of the Splunk Academic Alliance Program

The Splunk Community is more than just an online forum — it’s a network of passionate users, administrators, ...

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...