Splunk Enterprise Security: From Detection to Investigation

Event investigation in Splunk Enterprise Security begins with understanding the Detection and the entity it points to, continues with verifying contributing events, enriching Asset and Identity, building a Timeline and searching for related activity, and ends with Disposition, documentation, and feedback for the Detection. In Splunk ES 8, the terms Finding and Analyst Queue are more common; in earlier versions, you might see Notable and Incident Review.
Splunk Enterprise Security — or Splunk ES — adds a Security Operations layer on top of Splunk's search engine: Detections, asset and identity enrichment, Findings management, investigations, risk, and responses. The analyst's challenge is not just to "open an alert," but to understand what logic created it, what data contributed to it, what the true Scope is, and what is missing to make a decision.
The interface and terminology change between versions. In Splunk ES 7, Notable Event and Incident Review are common. In Splunk ES 8, Splunk uses Findings, Finding Groups, Analyst Queue, and Mission Control more. The professional principle remains the same: a Detection generates a finding; the analyst examines the context and evidence; and if there is real suspicion, the finding becomes or joins a structured investigation.
This article focuses on Risk-Based Alerting — RBA — because it clearly demonstrates the transition from a single alert to a behavioral story. The examples use lab data and illustrative risk scores only. A risk score should not be interpreted as an automatic conclusion of compromise.




