When you print the summary of an investigation through ES it does not include notes. Is there a way to add those? Alternatively is there a way touse SPL to find those notes, artifacts, and events, to...
When you print the summary of an investigation through ES it does not include notes. Is there a way to add those? Alternatively is there a way touse SPL to find those notes, a...
In order to visual a data table with 4 columns: time, resource1, resource2, duration. I know who to do this with data coming from different events. However in my case, all the data is s...
...30 minutes worth of logs before the crash.
In other tools I've used (Graphite, and New Relic) you can send special events for a code deploy and then those will be displayed in the graphs as a v...
I understand we can usethe following to look at theinvestigations created which are 'Active'.
|inputlookup append=t investigative_canvas_lookup
|inputlookup append=t investig...
Hi all!
I have something which sends me the START and the STOP of some processes.
I have this search that creates a timeline chart and, if in some processes we have just the START event, a...
I can see where we can create 'New Investigations', track or manage current investigations, delete or edit or remove existing investigations, but nothing to close theinvestigation. When you a...
Hi,
I need tousetheEventTimeline Viz to show a timeline of thethe different URLs been hit over time. This is the first time I used this visualization and I am struggling. At the m...