Splunk Enterprise Security

Where does the information related to Splunk Investigation get store in Splunk ?

payal_4296
New Member

Where is the data from the Splunk Enterprise Security (ES) Investigation Panel stored?
In the previous version, it seemed to be stored in a KV lookup, but I can't find it in the current 7.x version.

I understand that the Notable index holds information related to incidents from the Incident Review Dashboard.
How can we map Splunk Notables and their Investigations together to generate a comprehensive report in the current 7.x ES version?

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...