Splunk® Enterprise Security

Use Splunk Enterprise Security

Download manual as PDF

This documentation does not apply to the most recent version of ES. Click here for the latest version.
Download topic as PDF

Review an investigation in Splunk Enterprise Security

Revisit past investigations, or view a current investigation by clicking the title from the investigation bar or from the Investigations dashboard. Users with the capability to manage all investigations can view all investigations. Only collaborators on an investigation with write permissions can edit an investigation. See Manage access to investigations in Administer Splunk Enterprise Security.

Review an investigation for training or research purposes. Click an entry on an investigation to see all details associated with it.

  • For notes with file attachments, click the file name to download the file attachment.
  • For notable events, click View on Incident Review to open the Incident Review dashboard filtered on that specific notable event.
  • For action history entries, you can repeat the previously-performed action. For a search action history entry, click the search string to open it in search. For a dashboard action history entry, click the dashboard name to view the dashboard.

ES42 Timeline Big.png

Gain insight into an attack or investigation by viewing the entire investigation timeline or view only part of it by expanding or contracting the timeline. ES42 Timeline Zoom.png

Click the timeline to move it and scan the entries. View a chronological list of all timeline entries by clicking the list icon, or refine your view of the timeline using filters. You can filter by type or use the Filter box to filter by title.

Last modified on 18 January, 2018
PREVIOUS
Collaborate on an investigation in Splunk Enterprise Security
  NEXT
Share or print an investigation in Splunk Enterprise Security

This documentation applies to the following versions of Splunk® Enterprise Security: 4.7.0, 4.7.1, 4.7.2, 4.7.3, 4.7.4, 4.7.5, 4.7.6


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters