Hello,
We are using SplunkEnterpriseSecurityand I was just wondering if there is any way to add multiple collaborators at once to aninvestigation or to make it visible to the analyst to see t...
Is there a way to update the default collection or create a custom collection of swimlanes for the investigator dashboards for Splunk for EnterpriseSecurity?
For example, Asset Investigator has t...
Hi all,
I'm using ES 4.7.3 and as far as I know there is only the option to add collaborators one at a time to aninvestigation. This doesn't work well with our existing structure of incident r...
I have a notable event seen inSplunkEnterpriseSecurity's Security Posture dashboard.
I have reviewed it and determined it to be a false positive.
I want to remove it from view on the Security...
Some users reported that the investigations functionality is not available for them in the EnterpriseSecurity app. What role/capability should I assign to them?
I am looking for advices on how to plan the backup and storage of "My Investigations" data in the SplunkEnterpriseSecurity (ES).
Two questions regarding this:
1- How to configure and manage t...
We use the Investigations as part of our case management process. With that said, is there any way to get data oninvestigations? We would like to get data such as but not limited to:
Count o...
...croll to the bottom to see it. The issue doesn't occur until you sort any column or adjust the number per page.
Does anyone else have ES 5.2.0 and see this issue? It makes reviewing investigations a b...
Hi, i am trying to solve issue I encountered with enterprisesecurity. Our company has webserver that is accessible from internal network and from internet. It uses two IP addresses (internal and e...