Splunk Enterprise Security

ES - Notables | fetch correlated/contributing events for the triggered time in search app

CryoHydra
Path Finder

Hi,

In incident review dashboard i have assigned some notables to me, instead of reviewing one by one i wanted to review events for all notables in single attempt through search app.

e.g) Notable for excessive firewall deny rule - triggered for the time period 1AM to 5AM --> i need to review correlated/contributing events by opening the incident

e.g) excessive failed logon - triggered for 3AM to 8AM

both notable in incident review dash board is assigned to me and based on search properties i can get all notables assigned to me (search query) and can be used in search app, however i want to fetch contributing events for the notable in search app itself based on triggered time ? how can we go over this ?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...