Customize investigations in Splunk Asset and Risk Intelligence
You can customize your investigation by adding notes to assets and identities.
Create and manage notes for assets and identities
You can save additional data about assets and identities by creating a note associated with the asset or identity. For example, you might add a note that explains when you expect an asset to be decommissioned or why an account was created.
To create a note, complete the following steps:
- In Splunk Asset and Risk Intelligence, select Investigation from the main menu navigation bar.
- From the drop-down list, select either Asset investigation or Identity investigation.
- Enter the asset or identity you want to add a note to.
- Select Submit.
- Select the edit icon (
) on the Record panel.
- Select Add note.
- Enter your note.
- Select Add.
You can also manage your existing notes by selecting the edit icon ( ) or the delete icon (
).
Investigate assets and identities in Splunk Asset and Risk Intelligence | Use Splunk Asset and Risk Intelligence data with Splunk Enterprise Security |
This documentation applies to the following versions of Splunk® Asset and Risk Intelligence: 1.1.1
Feedback submitted, thanks!