Splunk Enterprise Security

where to check notable status ? not from ES app but from logs.

srisahitya_v
Communicator

Hello,

My question is regarding "Splunk App for Enterprise Security".

This app will trigger Notables and logging at index=Notable

Once I have change the status of a notable to inprogress Or pending, where it logged?

I would like to make a search query to find out from past 1 month how my team responded/closed the notables.

could you please help.

0 Karma

jkat54
SplunkTrust
SplunkTrust

it’s in the kvstore

They have macros to help you retrieve the data:

http://dev.splunk.com/view/enterprise-security/SP-CAAAFBA.

I believe you’re looking for incident_review:

 | `incident_review`
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...

Join Us at the Builder Bar at .conf24 – Empowering Innovation and Collaboration

What is the Builder Bar? The Builder Bar is more than just a place; it's a hub of creativity, collaboration, ...