When you print the summary of an investigation through ES it does not include notes. Is there a way to add those? Alternatively is there a way touse SPL to find those notes, a...
I understand we can usethe following to look at theinvestigations created which are 'Active'.
|inputlookup append=t investigative_canvas_lookup
|inputlookup append=t investig...
...ode.
We see the correct time and date that theevent was logged into ES Investigations. But when we print the document, the time and date change to January 18, 1970
What could c...
Hi all!
I have something which sends me the START and the STOP of some processes.
I have this search that creates a timeline chart and, if in some processes we have just the START event, a...
Running Splunk Splunk Enterprise, Version:7.3.3Build:7af3758d0d5e, we can not usetimeline wiz as we have random errors with the message "Failed to load source for EventTimeline Viz v...
...ndexed events and displays a count of '0' for the interpolated days. So far, so good.
What I have not yet been able to figure out is how to extend thetimeline from the last indexed eventtothe p...