Add ESCU annotations to correlation searches and analytics stories

Add and edit annotations from Enterprise Security Content Update (ESCU) to correlation searches and analytic stories in the use case library of Splunk Enterprise Security to enrich your security content.

Add annotations to a correlation search

View annotations in analytic stories from the use case library

View annotations that you added to the searches in the Analytic Story details page of the use case library.

  1. From the Splunk ES menu bar, select Configure > Content > Use Case Library.
  2. From the use cases filters on the left, click Cloud Security.
  3. From an Analytic Story, such as AWS Cross Account Activity, click the greater than ( >) symbol to expand the display.
  4. Scroll to Framework Mapping to view the annotation types supported by the Use Case Library.
  5. Click the name of the Analytic Story. For example, click AWS Cross Account Activity.
    The Analytic Story Details page opens for the story.
  6. Scroll to Cyber Security Framework Attributes to see the various ESCU annotation types associated with the analytic story.

See also
Use security framework annotations in correlation searches
Edit a correlation search