Skip to main content
Warning
This app is archived. App archiving documentation
Threat Activity Drilldown for ES app icon

Threat Activity Drilldown for ES

*** Deprecated as of Splunk ES 4.7, as this functionality was built into ES 4.7 *** *** Please do not use with ES 4.7 or newer version! ***Built by David Veuve
splunk product badge

Default Version 1.1

April 14, 2016

Compatibility

Splunk Enterprise

Rating
5
(1)

Log in to rate this app

Support
Archived Add-on

*** Deprecated as of Splunk ES 4.7, as this functionality was built into ES 4.7 *** *** Please do not use with ES 4.7 or newer version! *** This search add-on contains adds workflow actions to the ES Notable Event and the ES Threat Activity events so that an analyst looking at either can drill down from a threat activity indicator to look at the underlying raw events.