Splunk Enterprise Security

where to check notable status ? not from ES app but from logs.

srisahitya_v
Communicator

Hello,

My question is regarding "Splunk App for Enterprise Security".

This app will trigger Notables and logging at index=Notable

Once I have change the status of a notable to inprogress Or pending, where it logged?

I would like to make a search query to find out from past 1 month how my team responded/closed the notables.

could you please help.

0 Karma

jkat54
SplunkTrust
SplunkTrust

it’s in the kvstore

They have macros to help you retrieve the data:

http://dev.splunk.com/view/enterprise-security/SP-CAAAFBA.

I believe you’re looking for incident_review:

 | `incident_review`
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...