Share or print an investigation in Splunk Enterprise Security
Note:
The documentation for Splunk Enterprise Security versions 8.0 and higher have been rearchitected from previous versions, causing some links to have redirect errors. For documentation on version 8.0, see Splunk Enterprise Security 8.x documentation.
To share an investigation with someone that does not use Splunk Enterprise Security, such as for auditing purposes, you can print any investigation or save any investigation as a PDF.
- From the investigation, click the
icon. Splunk Enterprise Security generates a formatted version of the investigation timeline with entries in chronological order. The order of the entries in the printout remains in the original order, even if you manually edit the times so that they show up differently in the user interface.
- Print the investigation or save it as a PDF using the print dialog box options.