I've been searching for the same answer, as Splunk ES is is limiting in the regards. Most our other tools are found elswhere - to expedite the review or mitigation, it would be very helpful to add a link in the next steps to say go to the EDR, the Proofpoint Server, O365 etc... vs. the SOC analyst needing to fumble through his/her bookmarks etc.. If this doesn't exist, I sure how it's on the roadmap.
... View more