Security

SE-IncidentReviewDashboard- Need metrics of Notables by Investigation Options

vn_g
Path Finder

In Splunk Enterprise Security , Incident Review Dashboard , I am adding 2 different Investigation Option to the notables by clicking on "Add Event to Investigation". 

Now , my requirement is to find out the metrics of each Invegistation Option. For example , How many notables exist with a particular investigation Option. Is it possible?

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...