Add users or assets to investigations in Splunk Enterprise Security
To add a user or asset to a new or existing investigation, ensure data related to that user or asset is present in the Risk Data Model. See Configure asset and identity data for UEBA in Splunk Enterprise Security.
Add a user or asset to a new or existing investigation from the User analysis or Asset analysis page in Splunk Enterprise Security. This can help you quickly act on unusual behavior without leaving the analysis workflow.