One of the easiest and most powerful ways to empower your team is to create and embed automated Investigation Templates (docs). Analysts don’t need to know what templates are available ahead of time: instead, they get Graphistry links embedded into their existing workflows. For example, you can augment alert emails with targeted investigation links, or add contextual links to any web dashboard. This is great for tasks like recommending particular kinds of investigations, and putting contextual entity views in reach at the right time.
The video tutorial walks through creating an investigation template and embedding links into Splunk as contextual Workflow Actions:
Next steps & further reading