Manage and customize investigation statuses in Splunk Enterprise Security
Starting in version 5.0.0, you can add statuses to investigations. After upgrading to this version, investigations that did not have a status are assigned the New status.
To change the status of an investigation, an analyst must have the transition_reviewstatus-<x>_to_<y>
capability for the statuses that they want to transition between. The ess_analyst role and the ess_admin role have those capabilities for all statuses by default. Modifying status transitions for investigations modifies these capabilities.
To make changes to statuses as an analyst, you must have the edit_reviewstatuses
capability. The ess_admin role has this capability by default. See Configure users and roles in the Installation and Upgrade Manual.
Create an investigation status
Create a status for analysts to select when performing an investigation.
If you restrict status transitions, update status transitions after creating a status, otherwise analysts will be unable to select the new status. See Restrict status transitions for investigations in this topic.
- From the Enterprise Security toolbar, select Configure > Incident Management > Status Configuration.
- (Optional) Select the Investigation tab to review existing investigation statuses.
- Select Create New Status > Investigation.
- Type a Label that appears as the name of the status on the investigation.
For example, Waiting on Desktop IT. - (Optional) Type a Description that appears on the Status Configuration page to describe the status.
For example, Investigation is waiting for desktop IT to perform additional remediation or forensics steps. - (Optional) Select the check box for Default Status to set this status as the default for newly-created investigations.
- (Optional) Select the check box for End Status to set this status as a possible last status for an investigation.
- (Optional) Deselect the check box for Enabled to create the status without allowing anyone to use it yet.
- Update the user roles that are able to transition an investigation from this new status, for example Waiting on Desktop IT, to another status, such as Closed. If you do not select any roles that can transition from this status to another one, no one will be able to move the investigation to a different status after transitioning the investigation to this status.
- Click Save.
Restrict status transitions for investigations
The status transitions that can be made on an investigation define the path of an investigation. By default, an investigation in any status can be changed to any other status. For example, someone can change the status of an investigation in the New status to any other status, such as Closed.
You can restrict the statuses that analysts can choose when investigating. Determine which statuses to require, and whether analysts must follow a specific sequence of statuses before completing an investigation. Determine whether any roles can bypass the full sequence of statuses.
This example walks you through setting up restricting status transitions for analysts. Restrict status transitions so that analysts must follow a path from New, to In Progress or Pending, to Resolved, then to Closed.
1 | 2 | 3 | 4 |
---|---|---|---|
New | In Progress Pending |
Resolved | Closed |
Prerequisites
- You must have the ess_admin role or your role must be assigned the Edit Statuses capability. For more information about user roles and capabilities, see Configure users and roles in the Installation and Upgrade Manual.
- On the Splunk Enterprise Security toolbar, select Configure > Incident Management > Status Configuration.
- Click the Investigation tab.
- Restrict the transitions from the New status. Select the New status to open the Edit Investigation Status page.
- In Status Transitions, select the roles for the Resolved status and deselect the check box for the ess_analyst role.
- Select the roles for the Closed status and deselect the check box for the ess_analyst role.
- Click Save to save the changes to the New status.
- Restrict the transitions on the In Progress and Pending statuses to prevent the ess_analyst role from transitioning to New or to Closed.
- Click the Investigation tab and select the In Progress status.
- In Status Transition, select the roles for the New status and deselect the check box for the ess_analyst role. Repeat for the Closed status.
- Click Save to save the changes to the In Progress status. Repeat those steps for the Pending status.
- Restrict the Resolved status. Click the Investigation tab and select the Resolved status.
- In Status Transition, select the roles for the New status and deselect the check box for the ess_analyst role. Repeat for the In Progress and Pending statuses.
- Click Save to save the changes to the Resolved status.
- Restrict the transitions for the Closed status. Click the Investigations tab and select the Closed status.
- In Status Transition, select the roles for the New status and deselect the check box for the ess_analyst role. Repeat for the In Progress, Pending, and Resolved statuses.
- Click Save to save the changes for the Closed status.
Administer and customize the investigation workbench | Correlation search overview for Splunk Enterprise Security |
This documentation applies to the following versions of Splunk® Enterprise Security: 5.0.0, 5.0.1, 5.1.0, 5.1.1, 5.2.0, 5.2.1, 5.2.2, 5.3.0, 5.3.1, 6.0.0, 6.0.1, 6.0.2, 6.1.0, 6.1.1, 6.2.0, 6.3.0 Cloud only, 6.4.0, 6.4.1, 6.5.0 Cloud only, 6.5.1 Cloud only, 6.6.0, 6.6.2
Feedback submitted, thanks!