Splunk Enterprise Security

Splunk Enterprise Security: It is possible to customize the Incident Review default search?

hcannon
Path Finder

Enterprise Security automatically loads the Incident Review search to look for Status "All", Owner "All", Security Domain "All", Last 24 hours.

Anyone know a way to change the page to, by default, load only new incidents? Or change the time parameter? I feel like this should be something you can change easily in the app configuration, but I haven't run across anything to edit this pages default incident search.

0 Karma
1 Solution
Get Updates on the Splunk Community!

Introducing Splunk Enterprise Security 8.0!

Join us on Wednesday, November 20 to learn about Splunk Enterprise Security 8.0!To enhance SOC efficiency, ...

Mastering Threat Hunting

Register to watch Mastering Threat Hunting on Monday, November 18Join us for an insightful talk where we dive ...

Upcoming Community Maintenance: 10/28

Howdy folks, just popping in to let you know that the Splunk Community site will be in read-only mode ...