Splunk Enterprise Security

Splunk Enterprise Security: Where can I find the incident review logs (incident_review.csv)?

bipin82
New Member

Hello:

Can anyone help me in finding the Incident review logs? Will it be there in the Indexer or the Search heads? I tried doing an ssh to both Indexer and search heads, but couldn't find the incident_review.csv file.

Thanks

Bipin

0 Karma

Vinayak
New Member

in es apps search tab in searching window just search for `notable`. you will get all the deatils.

0 Karma

LukeMurphey
Champion

Newer versions of ES no longer store the Incident Review data in a lookup file. It is now kept in the KV store. The collection name is "es_notable_events". You can view this in search using inputlookup:

| inputlookup append=t es_notable_events
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...