<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Correlation search not showing notable in Incident Review? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Correlation-search-not-showing-notable-in-Incident-Review/m-p/630637#M11309</link>
    <description>&lt;P&gt;Hi Splunkers.&lt;/P&gt;
&lt;P&gt;I have noticed a strange behavior from Splunk, I have a correlation search that I have created a while ago, ensured to select "Notable" under the&amp;nbsp;&lt;STRONG&gt;Adaptive Responsive section&lt;/STRONG&gt;&amp;nbsp;so that it creates a notable, also tested that when I run the search manually it produced results. BUT it does not generate notables in the&amp;nbsp;&lt;STRONG&gt;Incident Review&lt;/STRONG&gt;&amp;nbsp;dashboard!&lt;BR /&gt;&lt;BR /&gt;So I went and searched&amp;nbsp;index=notable and found 4 events for this&amp;nbsp;correlation search in the last 30 days!&lt;BR /&gt;Then I checked the same index for another&amp;nbsp;correlation search that DOES&amp;nbsp;generate notables in the&amp;nbsp;Incident Review&amp;nbsp;dashboard (4 notables in the last 30 days) and indeed I found 4 events in the notable index!&lt;BR /&gt;&lt;BR /&gt;I also used the "Correlation Search Audit" app (&lt;A href="https://splunkbase.splunk.com/app/4144)" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/4144)&lt;/A&gt;&amp;nbsp;and Indeed this app shows that this&amp;nbsp;correlation search has been triggered 4 times in the last 30 days!&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The search does not have any lookups (In case you asked about the &lt;SPAN&gt;permissions of the lookups&lt;/SPAN&gt;).&lt;BR /&gt;The search does use the Web data model (and it has &lt;SPAN&gt;Global permissions&lt;/SPAN&gt;).&lt;BR /&gt;&lt;BR /&gt;I'm using the admin user so I have&amp;nbsp;sufficient privileges.&lt;BR /&gt;&lt;BR /&gt;I'm using:&lt;BR /&gt;Splunk Enterprise version: 8.1.0&lt;BR /&gt;Enterprise Security version: 6.2.0&lt;BR /&gt;OS:&amp;nbsp;Red Hat Enterprise Linux Server 7.7 (Maipo)&lt;BR /&gt;&lt;BR /&gt;Any Idea why this is happening?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 13 Feb 2023 17:13:42 GMT</pubDate>
    <dc:creator>muradgh</dc:creator>
    <dc:date>2023-02-13T17:13:42Z</dc:date>
    <item>
      <title>Correlation search not showing notable in Incident Review?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Correlation-search-not-showing-notable-in-Incident-Review/m-p/630637#M11309</link>
      <description>&lt;P&gt;Hi Splunkers.&lt;/P&gt;
&lt;P&gt;I have noticed a strange behavior from Splunk, I have a correlation search that I have created a while ago, ensured to select "Notable" under the&amp;nbsp;&lt;STRONG&gt;Adaptive Responsive section&lt;/STRONG&gt;&amp;nbsp;so that it creates a notable, also tested that when I run the search manually it produced results. BUT it does not generate notables in the&amp;nbsp;&lt;STRONG&gt;Incident Review&lt;/STRONG&gt;&amp;nbsp;dashboard!&lt;BR /&gt;&lt;BR /&gt;So I went and searched&amp;nbsp;index=notable and found 4 events for this&amp;nbsp;correlation search in the last 30 days!&lt;BR /&gt;Then I checked the same index for another&amp;nbsp;correlation search that DOES&amp;nbsp;generate notables in the&amp;nbsp;Incident Review&amp;nbsp;dashboard (4 notables in the last 30 days) and indeed I found 4 events in the notable index!&lt;BR /&gt;&lt;BR /&gt;I also used the "Correlation Search Audit" app (&lt;A href="https://splunkbase.splunk.com/app/4144)" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/4144)&lt;/A&gt;&amp;nbsp;and Indeed this app shows that this&amp;nbsp;correlation search has been triggered 4 times in the last 30 days!&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The search does not have any lookups (In case you asked about the &lt;SPAN&gt;permissions of the lookups&lt;/SPAN&gt;).&lt;BR /&gt;The search does use the Web data model (and it has &lt;SPAN&gt;Global permissions&lt;/SPAN&gt;).&lt;BR /&gt;&lt;BR /&gt;I'm using the admin user so I have&amp;nbsp;sufficient privileges.&lt;BR /&gt;&lt;BR /&gt;I'm using:&lt;BR /&gt;Splunk Enterprise version: 8.1.0&lt;BR /&gt;Enterprise Security version: 6.2.0&lt;BR /&gt;OS:&amp;nbsp;Red Hat Enterprise Linux Server 7.7 (Maipo)&lt;BR /&gt;&lt;BR /&gt;Any Idea why this is happening?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2023 17:13:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Correlation-search-not-showing-notable-in-Incident-Review/m-p/630637#M11309</guid>
      <dc:creator>muradgh</dc:creator>
      <dc:date>2023-02-13T17:13:42Z</dc:date>
    </item>
    <item>
      <title>Re: Correlation search not showing notable in Incident Review</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Correlation-search-not-showing-notable-in-Incident-Review/m-p/630638#M11310</link>
      <description>&lt;P&gt;Perhaps the NE is being suppressed.&amp;nbsp; Check by going to Configure-&amp;gt;Incident Management-&amp;gt;Notable Event Suppressions&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2023 13:15:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Correlation-search-not-showing-notable-in-Incident-Review/m-p/630638#M11310</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-02-13T13:15:07Z</dc:date>
    </item>
    <item>
      <title>Re: Correlation search not showing notable in Incident Review</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Correlation-search-not-showing-notable-in-Incident-Review/m-p/630639#M11311</link>
      <description>&lt;P&gt;I have checked but nope, it's not&amp;nbsp;&lt;SPAN&gt;suppressed&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2023 13:23:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Correlation-search-not-showing-notable-in-Incident-Review/m-p/630639#M11311</guid>
      <dc:creator>muradgh</dc:creator>
      <dc:date>2023-02-13T13:23:41Z</dc:date>
    </item>
    <item>
      <title>Re: Correlation search not showing notable in Incident Review</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Correlation-search-not-showing-notable-in-Incident-Review/m-p/630640#M11312</link>
      <description>&lt;P&gt;What you are describing happens when the correlation rule is suppressed.&amp;nbsp; Did you check the suppression page for this alert ?&amp;nbsp;&lt;BR /&gt;Secondly when you ran the search manually , did it produce results in a tabular format ?&amp;nbsp; Typically correlation search results are in a tabular format.&lt;BR /&gt;&lt;BR /&gt;P.S Pls upvote if this helps.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2023 13:24:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Correlation-search-not-showing-notable-in-Incident-Review/m-p/630640#M11312</guid>
      <dc:creator>neerajs_81</dc:creator>
      <dc:date>2023-02-13T13:24:09Z</dc:date>
    </item>
    <item>
      <title>Re: Correlation search not showing notable in Incident Review</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Correlation-search-not-showing-notable-in-Incident-Review/m-p/630641#M11313</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I have checked but nope, it's not&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;suppressed.&lt;BR /&gt;And yes the search produces&amp;nbsp;results in a tabular format&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2023 13:26:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Correlation-search-not-showing-notable-in-Incident-Review/m-p/630641#M11313</guid>
      <dc:creator>muradgh</dc:creator>
      <dc:date>2023-02-13T13:26:31Z</dc:date>
    </item>
  </channel>
</rss>

