Splunk Enterprise Security

Where does the information related to Splunk Investigation get store in Splunk ?

payal_4296
New Member

Where is the data from the Splunk Enterprise Security (ES) Investigation Panel stored?
In the previous version, it seemed to be stored in a KV lookup, but I can't find it in the current 7.x version.

I understand that the Notable index holds information related to incidents from the Incident Review Dashboard.
How can we map Splunk Notables and their Investigations together to generate a comprehensive report in the current 7.x ES version?

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...