To share an investigation with someone that does not use Splunk Enterprise Security, such as for auditing purposes, you can print any investigation or save any investigation as a PDF.
- From the investigation, click the icon. Splunk Enterprise Security generates a formatted version of the investigation timeline with entries in chronological order. The order of the entries in the printout remains in the original order, even if you manually edit the times so that they show up differently in the user interface.
- Print the investigation or save it as a PDF using the print dialog box options.
Review an investigation in Splunk Enterprise Security
Refer to your action history in Splunk Enterprise Security
This documentation applies to the following versions of Splunk® Enterprise Security: 4.7.0, 4.7.1, 4.7.2, 4.7.3, 4.7.4, 4.7.5, 4.7.6, 5.0.0, 5.0.1, 5.1.0, 5.1.1, 5.2.0, 5.2.1, 5.2.2, 5.3.0, 5.3.1, 6.0.0, 6.0.1, 6.0.2, 6.1.0, 6.1.1, 6.2.0, 6.3.0 Cloud only, 6.4.0, 6.4.1, 6.5.0 Cloud only