Hello,
My question is regarding "Splunk App for Enterprise Security".
This app will trigger Notables and logging at index=Notable
Once I have change the status of a notable to inprogress Or pending, where it logged?
I would like to make a search query to find out from past 1 month how my team responded/closed the notables.
could you please help.
it’s in the kvstore
They have macros to help you retrieve the data:
http://dev.splunk.com/view/enterprise-security/SP-CAAAFBA.
I believe you’re looking for incident_review:
| `incident_review`