Skip to main content
User guide

Investigations

The archive of investigation, triage, explanation and report conclusions: browse by type and time, search, follow up on the home page.

Every paid-engine run (investigation, triage, incident report) and every "Explain these results" stores one record in the KV store (copilot_analysis), without raw log data. This page is the way back to them, in every edition.

Investigations

List

ColumnNotes
TypeInvestigation / triage / explanation / report; tabs filter by type
TitleRule name for investigations, batch summary for triage, log type for explanations
SeverityThe conclusion's level, same colour scale as everywhere else
SubjectThe main host / user / IP
TimeWhen generated; "N more" pages by cursor

The search box matches title, summary and subject as substrings, server-side.

Detail

Open a record for the full conclusion, timeline / attack chain (investigations), cluster table (triage), model and engine, token usage. Investigations that were written back to ES or opened as tickets show the notable status and ticket key at the bottom.

Detail

"Follow up" carries the record's context into a new conversation on the home page, so "which other hosts did this IP touch" can be asked next.

Retention

Records do not expire. KV store capacity is Splunk's; clean up by deleting documents in the collection, or delete by type on this page (admin).

On this page