Splunk Enterprise Security

short id incident review

Mohammed123
Loves-to-Learn Everything

some issues with short id we cant able to search through incident review, actually the paloalto saor is integrated with splunk, some incidents will changing their status and short id creating from xsoar its reflecting in splunk but we cant able to search with that short id in incident review. only short id created by Xsoar we can't able to searchable remaining shortid in splunk can be searchable . Please provide me how to resolve this issue 

Labels (1)
Tags (1)
0 Karma

Mohammed123
Loves-to-Learn Everything

Hello Please give me suggestion to resolve this 

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...