Hey everyone, I've been evaluating Splunk ES for my team for a few months now, and I was really excited about the mobile app. The idea of getting alerts and being able to triage from anywhere seemed like a game-changer.
But after trying to use it during an actual simulated incident... I'm struggling to see the value? It feels more like a notification mirror than a response tool. For example, when I got an alert about suspicious logins, all I could really do on the app was acknowledge it and see a basic summary. I couldn't drill into the related notable events easily, couldn't run a quick ad-hoc search to scope the user's other activity, and pivoting felt clunky.
Maybe I'm missing something? How are others using it effectively? Is the workflow just meant for alerting a human to go to their laptop, or are there tricks to actually doing meaningful triage from the app? I'm curious about real-world use cases, because on the surface, it seems like a missed opportunity for true mobile IR.
Also, from a budgeting perspective, does the mobile functionality factor into the value proposition for anyone? Or is it just a "nice-to-have" that doesn't really move the needle?