Splunk Enterprise Security

Splunk Enterprise Security: If an analyst added a notable event to an investigation, how does another analyst open that notable event to review it?

panovattack
Communicator

If an analyst has added a notable event to an investigation, how does another analyst open that notable event to review it? There does not seem to be an option to view the raw event referenced in the timeline or jump to the all the notable events for an investigation. The same goes for Splunk Events.

0 Karma
1 Solution

panovattack
Communicator

I believe this was fixed in updates to ES.

View solution in original post

0 Karma

panovattack
Communicator

I believe this was fixed in updates to ES.

0 Karma

smoir_splunk
Splunk Employee
Splunk Employee

@panovattack I wanted to follow up on my answer and let you know that in ES 4.1 you can do this! When you add a notable event there is also a link to view the notable event on incident review. notable event on an investigation timeline showing the information on notable events and a link to view the notable event on incident review

smoir_splunk
Splunk Employee
Splunk Employee

There is no way to do that in the latest version, unfortunately. You can view only notable events or splunk events on an investigation by filtering on a type: of notable event or splunk event.

In the latest release, however, there is no way to click through to the raw events from the investigation timeline.

AndySplunks
Communicator

Have you tried going to Actions, Show Source for the Notable Event? Below is a screenshot from my system:

alt text

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...