Professional Documents
Culture Documents
Managing Investigations in Splunk Enterprise Security Slides
Managing Investigations in Splunk Enterprise Security Slides
Enterprise Security
Joe Abraham
CYBERSECURITY CONSULTANT
@joeabrah www.joeabrahamtech.com
Create and modify investigations
Can be from notable events or
manually created
Investigations Provides workbench for
Dashboard investigation collateral
- Notes
- Artifacts
- Events
Explore investigations dashboard
Overview - Demo
Investigation management
- Demo
Course review
Let’s wrap!
Splunk ES User Guide
Working with Investigations
Investigations Dashboard
No edit button like other dashboards