Hi Community,
Not sure how to explain this... But the whole timeline looks like this:
Now we have 2 notable events to investigate, even though the computer, the usb stick and the malicious file are the same.
If the analyst did not have looked for other related events he might have thought that those two alerts were completely unrelated.
Is there a way to group those two notable alerts and "make Splunk" show only the most recent alert of those two?
Thanks
Jose.
I think this is what our ES users have been requesting for the past few years now. As of 4.7, I don't think the functionality is there. I'm not sure if they added it in 5.0.
Hopefully since it seems like ITSI can do it, they'll make it available in ES soon.