Splunk Enterprise Security

where to check notable status ? not from ES app but from logs.

srisahitya_v
Communicator

Hello,

My question is regarding "Splunk App for Enterprise Security".

This app will trigger Notables and logging at index=Notable

Once I have change the status of a notable to inprogress Or pending, where it logged?

I would like to make a search query to find out from past 1 month how my team responded/closed the notables.

could you please help.

0 Karma

jkat54
SplunkTrust
SplunkTrust

it’s in the kvstore

They have macros to help you retrieve the data:

http://dev.splunk.com/view/enterprise-security/SP-CAAAFBA.

I believe you’re looking for incident_review:

 | `incident_review`
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...