Splunk Enterprise Security

Splunk Enterprise Security: It is possible to customize the Incident Review default search?

hcannon
Path Finder

Enterprise Security automatically loads the Incident Review search to look for Status "All", Owner "All", Security Domain "All", Last 24 hours.

Anyone know a way to change the page to, by default, load only new incidents? Or change the time parameter? I feel like this should be something you can change easily in the app configuration, but I haven't run across anything to edit this pages default incident search.

0 Karma
1 Solution
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...