Review records from native threat collections in Splunk Enterprise Security
- In Splunk Enterprise Security, select Mission Control.
- Select an investigation from the analyst queue to open the side panel.
- Select View investigation to open the investigation overview page.
- Select the Intelligence tab.
- Select an observable from the list.
- Expand the section called All records from native threat collections. You can select any of these records to find key-value pairs such as domains, IPs, indicators, and metadata.