See More, Act Faster, and Simplify Investigations with Customizable Workflows from Splunk Enterprise Security 7.2

Security Olivia Henderson
In our latest release of Splunk Enterprise Security 7.2, we are excited to introduce capabilities that deliver an improved workflow experience for simplified investigations; enhanced visibility and reduced manual workload; and customized investigation workflows for faster decision-making. The majority of these updates and new features were requested directly from Splunk Enterprise Security (ES) users and submitted through the Splunk Ideas portal. Keep the great ideas and suggestions coming — we’re listening!

With these new capabilities, ES helps you see more, act faster, and simplify your investigations. Let’s take a look!

Improved Workflow Experience for Simplified Investigations

Enhanced Visibility and Reduced Manual Workload

Security analysts need to reduce manual workload. With the new Auto Refresh in Incident Review, ES will automatically showcase the most up-to-date events for the SOC. Administrators can now customize and control the frequency of the auto refresh. This ensures that analysts are seeing the latest notable events to help them make efficient and fast decisions, and save time by reducing manual work.

Furthermore, security analysts can currently prioritize notable events within Splunk Enterprise Security, but often want to visualize it by date and time. That’s why we’re bringing back the Timeline function in Incident Review. Analysts can now view related events across a specific time frame. This interactive timeline for notables supports analysts by enabling the SOC to quickly gain insight into anomalous activity, such as an unusually high number of notables around a certain time, and therefore prioritize time-sensitive critical incidents.

Customize Investigation Workflows for Faster Decision-Making

Large Security Operations Centers with multiple teams often struggle to make fast decisions when they are overwhelmed with security events. ES 7.2 introduces optional enhancements to the Incident Review dashboard that provides a more customizable experience when investigating notable events.

Analysts are now able to customize and configure the Incident Review dashboard with table filters and columns that provide the capability for practitioners to look at events that matter to them. Additionally, they can now create saved views of their customized Incident Review Dashboard and share them with other Enterprise Security analysts. This allows analysts with different use cases to share their tailored views of notable events with other incident investigators in order to seamlessly collaborate on notable events. Splunk ES Administrators also have access to a new level of controls on the analyst experience in Incident Review, including the ability to configure default views for all users.

Upgrade Today!

Splunk Enterprise Security 7.2 updates are available today in both cloud and on-prem environments. As we mentioned, the majority of updates in this release were requests that came directly from users. We’re listening! If you have ideas and requests, please submit them to Splunk Ideas.

Ready to get hands on with Enterprise Security 7.2? Register for our Tech Talk!

To learn more about Splunk Enterprise Security 7.2, check out the release notes and the Splunk Enterprise Security website.

Happy Splunking!

Related Articles

REvil Ransomware Threat Research Update and Detections
Security
8 Minute Read

REvil Ransomware Threat Research Update and Detections

On July 2, 2021, REvil group used Kaseya to distribute malware to its on-premises customers. Splunk has pushed out guidance to help understand and detect REvil. Learn more about the REvil ransomeware group, their tactics, and how to detect them using Splunk.
Build the SOC of the Future with Splunk and Cisco
Security
2 Minute Read

Build the SOC of the Future with Splunk and Cisco

Discover how Splunk and Cisco are transforming security operations centers with unified platforms, AI-driven threat detection, and real-time visibility. Learn key insights, challenges, and strategies to build a smarter, more resilient SOC for the future.
Splunk Security Content for Threat Detection & Response: June Recap
Security
2 Minute Read

Splunk Security Content for Threat Detection & Response: June Recap

Learn about the latest security content from Splunk.