Make changes to an investigation in Splunk Enterprise Security
Make changes to the entries on an investigation from the timeline list or slide view.
Change the title and description of an investigation
Change the title and description of an investigation from the investigation bar. For example, change the name of the investigation as your investigation progresses to more accurately describe the security incident you are investigating.
- From the investigation bar, click the icon. From the investigation view, click Edit.
- Change the title or description.
- Click Save.
Update the status of an investigation
Update the status of an investigation from the workbench, summary, or timeline view.
- While viewing the investigation, click Edit > Edit title, description, and status.
- Select a new status.
- Click Save.
You can also update the status of an investigation from the investigation bar.
- Click the icon and select your investigation.
- After loading your investigation into the investigation bar, click the icon and select a status.
- Click Save.
Similar to notable events, administrators can customize the statuses available to select, and restrict the status workflow. Because of this, you might not be able to transition from some statuses to other statuses. See Manage and customize investigation statuses in Administer Splunk Enterprise Security.
Delete investigation entries
You can delete investigation entries when viewing the investigation timeline list or slide views.
- Find the entry on the investigation.
- Click Action > Delete Entry.
- Click Delete to confirm deleting the entry.
To delete multiple entries:
- Click List to view the investigation as a list of entries.
- Select the check box next to the investigation entries that you want to delete.
- Click Action and select Delete.
- Click Delete to confirm deleting the entry.
Edit or delete a note
Edit a note by clicking on it in the investigation notes window.
- From the investigation bar, click the icon.
- Select the note.
- Edit the title, date, timeline display, the note itself, and add or delete attachments.
Alternately, go to the timeline list view to edit or delete the note entry.
- From the timeline tab, click List View.
- From the actions column, you will see both notes and timeline notes.
- Select Edit Entry to edit it or Delete Entry to delete it.
Change the title of an entry
You can change the title of an entry to make it more clear.
- Locate the notable event, Splunk event, action history item, or other entry on the investigation.
- From the Actions menu, click Edit.
- Change the title.
Add details to an investigation in Splunk Enterprise Security | Collaborate on an investigation in |
This documentation applies to the following versions of Splunk® Enterprise Security: 7.0.1, 7.0.2, 7.1.0, 7.1.1, 7.1.2, 7.2.0, 7.3.0, 7.3.1, 7.3.2
Feedback submitted, thanks!