The Incident Review dashboard is where analysts live. Engineers optimize this workspace by customizing table columns, adding drilldowns, and integrating workflow actions.
A Workflow Action allows an analyst to click on an IP in an alert and instantly query a 3rd party tool (like Shodan) without leaving Splunk.