<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk ES 8.0.2 missing drill down in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-8-0-2-missing-drill-down/m-p/740707#M12400</link>
    <description>&lt;P&gt;I'm following the same steps, but don't see the drill down appearing&lt;/P&gt;</description>
    <pubDate>Tue, 04 Mar 2025 10:11:35 GMT</pubDate>
    <dc:creator>muhammadfahimma</dc:creator>
    <dc:date>2025-03-04T10:11:35Z</dc:date>
    <item>
      <title>Splunk ES 8.0.2 missing drill down</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-8-0-2-missing-drill-down/m-p/740519#M12391</link>
      <description>&lt;P&gt;After a recent upgrade to Splunk ES 8.0.2, we have observed that none of the drill downs for detection based searches are available in the mission control screen anymore. Don't see any errors that might hint any abnormality. Has anyone come across a similar issue? How can this issue be debugged?&lt;/P&gt;</description>
      <pubDate>Sun, 02 Mar 2025 22:50:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-8-0-2-missing-drill-down/m-p/740519#M12391</guid>
      <dc:creator>muhammadfahimma</dc:creator>
      <dc:date>2025-03-02T22:50:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES 8.0.2 missing drill down</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-8-0-2-missing-drill-down/m-p/740525#M12394</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/31681"&gt;@muhammadfahimma&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please review the following, and I kindly request you to raise a Splunk support ticket.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/ES/8.0.2/Admin/InvestigateFindingsDrilldownSearchesDashboards" target="_blank"&gt;Investigate findings using drilldown searches and dashboards in Splunk Enterprise Security - Splunk Documentation&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 06:17:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-8-0-2-missing-drill-down/m-p/740525#M12394</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-03-03T06:17:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES 8.0.2 missing drill down</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-8-0-2-missing-drill-down/m-p/740544#M12395</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/31681"&gt;@muhammadfahimma&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe you may be experiencing a bug (BLUERIDGE-13575) which is a known issue with ES 8.0.2 (See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/ES/8.0.2/RN/KnownIssues" target="_blank"&gt;https://docs.splunk.com/Documentation/ES/8.0.2/RN/KnownIssues&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;If this is the issue then you may find the following workaround solves the issue until fixed in the product:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Workaround:
Remove `source` before sending to detection.
add `| fields - source` to end of search&lt;/LI-CODE&gt;&lt;P&gt;Either way, I would suggest raising a support case, as even if it is this particular bug they will be able to associate it to your account and keep you updated with progress and resolution.&lt;/P&gt;&lt;P&gt;Please let me know how you get on and consider adding karma to this or any other answer if it has helped.&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 09:02:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-8-0-2-missing-drill-down/m-p/740544#M12395</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-03T09:02:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES 8.0.2 missing drill down</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-8-0-2-missing-drill-down/m-p/740706#M12399</link>
      <description>&lt;P&gt;I don't think that is the case, the drilldowns are not appearing at all&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 10:11:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-8-0-2-missing-drill-down/m-p/740706#M12399</guid>
      <dc:creator>muhammadfahimma</dc:creator>
      <dc:date>2025-03-04T10:11:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES 8.0.2 missing drill down</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-8-0-2-missing-drill-down/m-p/740707#M12400</link>
      <description>&lt;P&gt;I'm following the same steps, but don't see the drill down appearing&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 10:11:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-8-0-2-missing-drill-down/m-p/740707#M12400</guid>
      <dc:creator>muhammadfahimma</dc:creator>
      <dc:date>2025-03-04T10:11:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES 8.0.2 missing drill down</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-8-0-2-missing-drill-down/m-p/740726#M12401</link>
      <description>&lt;P&gt;In that case&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/31681"&gt;@muhammadfahimma&lt;/a&gt;&amp;nbsp; I think it is best to get this raised with Splunk Support, they should let you know the reference number once it has been logged and you can track it on the Release Notes (&lt;A href="https://docs.splunk.com/Documentation/ES/latest/RN/NewFeatures" target="_blank"&gt;https://docs.splunk.com/Documentation/ES/latest/RN/NewFeatures&lt;/A&gt;) page.&lt;/P&gt;&lt;P&gt;Please let me know how you get on and consider adding karma to this or any other answer if it has helped.&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 11:15:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-8-0-2-missing-drill-down/m-p/740726#M12401</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-04T11:15:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES 8.0.2 missing drill down</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-8-0-2-missing-drill-down/m-p/740948#M12404</link>
      <description>&lt;P&gt;thank you&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp; i ended up creating a ticket with splunk support&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 16:15:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-8-0-2-missing-drill-down/m-p/740948#M12404</guid>
      <dc:creator>muhammadfahimma</dc:creator>
      <dc:date>2025-03-05T16:15:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES 8.0.2 missing drill down</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-8-0-2-missing-drill-down/m-p/753125#M12666</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/31681"&gt;@muhammadfahimma&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Did you get any updates from the Splunk team?&lt;/P&gt;&lt;P&gt;I have installed ES 8.2.0 on the on prem Splunk instance, created an EBD and added the drill-down searches in the Detection Editor, but these are missing in the Mission Control detection page.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2025 06:22:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-8-0-2-missing-drill-down/m-p/753125#M12666</guid>
      <dc:creator>SudhaP54</dc:creator>
      <dc:date>2025-09-16T06:22:52Z</dc:date>
    </item>
  </channel>
</rss>

