Splunk Enterprise Security

Where to add custom artifact types to use in the workbench?

jrodriguezap
Contributor

Hello everyone
In the Investigation view, in the Workbench section, I want to add a different artifact type than the ones that appear (asset, identity, file, url), I would like an artifact type: Device, and another type: Index.

Where to add custom artifact types to use in the workbench?

jrodriguezap
Contributor

Is there anyone who has gone through the same situation? maybe i found a solution

0 Karma

hieuba
Loves-to-Learn Lots

Hi @jrodriguezap , could you share your solution pls? 

0 Karma

DanielPi
Moderator
Moderator

Hi @hieuba -

I’m a Community Moderator in the Splunk Community. 
This question was posted 1 year ago, so it might not get the attention you need for your question to be answered. We recommend that you post a new question so that your issue can get the  visibility it deserves. To increase your chances of getting help from the community, follow these guidelines in the Splunk Answers User Manual when creating your post.

Thank you! 

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...