- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Where does the information related to Splunk Investigation get store in Splunk ?
payal_4296
New Member
12-18-2023
10:08 AM
Where is the data from the Splunk Enterprise Security (ES) Investigation Panel stored?
In the previous version, it seemed to be stored in a KV lookup, but I can't find it in the current 7.x version.
I understand that the Notable index holds information related to incidents from the Incident Review Dashboard.
How can we map Splunk Notables and their Investigations together to generate a comprehensive report in the current 7.x ES version?
