<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Investigations disappearing  in Analyst Queue in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Investigations-disappearing-in-Analyst-Queue/m-p/759795#M12876</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/315087"&gt;@Ian0706&lt;/a&gt;&amp;nbsp;Your issue&amp;nbsp;with investigations is actually documented in Splunk ES 8.4 under &lt;EM&gt;Known issues&lt;/EM&gt;. No workaround mentioned yet. Hence, re-install of the same version won't be effective. We usually maintain n-1 versions in Splunk as a best practice to avoid such issues and going forward, please review &lt;EM&gt;Known issues&lt;/EM&gt; for the version before doing a version upgrade to assess any potential impact due to upgrade.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk-comm.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/41875i375B6DB3DE67D522/image-size/large?v=v2&amp;amp;px=999" role="button" title="splunk-comm.png" alt="splunk-comm.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Ref:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://help.splunk.com/en/splunk-enterprise-security-8/release-notes-and-resources/8.4/splunk-enterprise-security-release-notes/known-issues" target="_blank" rel="noopener"&gt;Known issues | Splunk Enterprise, Splunk Cloud Platform (last updated 2026-02-04T21:32:01.448Z)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If this post addressed your question, you can:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Give it&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;karma&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;to show appreciation&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Mark it as the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;solution&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;if it solved your issue&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":heavy_check_mark:"&gt;✔️&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Add a&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;comment&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;if you’d like more details&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":pencil:"&gt;✏️&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;Acknowledging helpful answers keeps the community strong and motivates contributors to continue sharing their expertise.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 30 Mar 2026 18:22:25 GMT</pubDate>
    <dc:creator>kknairr</dc:creator>
    <dc:date>2026-03-30T18:22:25Z</dc:date>
    <item>
      <title>Investigations disappearing  in Analyst Queue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Investigations-disappearing-in-Analyst-Queue/m-p/759778#M12874</link>
      <description>&lt;P&gt;I have recently installed Splunk Enterprise Security v8.4 on a fresh Splunk instance after successfully using v8.2 on a previous instance. However I have an issue when using investigations. To even create an investigation I had to manually add the "default" investigation type. The issue I am having now is that the investigation pops up for a short time when refreshing the queue and then disappear after that. Is this a known issue, will this require an ESS reinstall?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="example2.gif" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/41874i0C571831DDE7DA54/image-size/medium?v=v2&amp;amp;px=400" role="button" title="example2.gif" alt="example2.gif" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2026 14:44:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Investigations-disappearing-in-Analyst-Queue/m-p/759778#M12874</guid>
      <dc:creator>Ian0706</dc:creator>
      <dc:date>2026-03-30T14:44:24Z</dc:date>
    </item>
    <item>
      <title>Re: Investigations disappearing  in Analyst Queue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Investigations-disappearing-in-Analyst-Queue/m-p/759779#M12875</link>
      <description>&lt;P&gt;I apologize for the awful GIF, i didn't know that it would play on a very fast repeat. However these investigations are also seen in the "mc_investigations_lookup".&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2026 15:07:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Investigations-disappearing-in-Analyst-Queue/m-p/759779#M12875</guid>
      <dc:creator>Ian0706</dc:creator>
      <dc:date>2026-03-30T15:07:50Z</dc:date>
    </item>
    <item>
      <title>Re: Investigations disappearing  in Analyst Queue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Investigations-disappearing-in-Analyst-Queue/m-p/759795#M12876</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/315087"&gt;@Ian0706&lt;/a&gt;&amp;nbsp;Your issue&amp;nbsp;with investigations is actually documented in Splunk ES 8.4 under &lt;EM&gt;Known issues&lt;/EM&gt;. No workaround mentioned yet. Hence, re-install of the same version won't be effective. We usually maintain n-1 versions in Splunk as a best practice to avoid such issues and going forward, please review &lt;EM&gt;Known issues&lt;/EM&gt; for the version before doing a version upgrade to assess any potential impact due to upgrade.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk-comm.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/41875i375B6DB3DE67D522/image-size/large?v=v2&amp;amp;px=999" role="button" title="splunk-comm.png" alt="splunk-comm.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Ref:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://help.splunk.com/en/splunk-enterprise-security-8/release-notes-and-resources/8.4/splunk-enterprise-security-release-notes/known-issues" target="_blank" rel="noopener"&gt;Known issues | Splunk Enterprise, Splunk Cloud Platform (last updated 2026-02-04T21:32:01.448Z)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If this post addressed your question, you can:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Give it&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;karma&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;to show appreciation&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Mark it as the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;solution&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;if it solved your issue&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":heavy_check_mark:"&gt;✔️&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Add a&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;comment&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;if you’d like more details&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":pencil:"&gt;✏️&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;Acknowledging helpful answers keeps the community strong and motivates contributors to continue sharing their expertise.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2026 18:22:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Investigations-disappearing-in-Analyst-Queue/m-p/759795#M12876</guid>
      <dc:creator>kknairr</dc:creator>
      <dc:date>2026-03-30T18:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: Investigations disappearing  in Analyst Queue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Investigations-disappearing-in-Analyst-Queue/m-p/759796#M12877</link>
      <description>&lt;P&gt;Thank you for the help. I did not think to check for a known issues page, I guess this calls for a downgrade.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2026 18:53:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Investigations-disappearing-in-Analyst-Queue/m-p/759796#M12877</guid>
      <dc:creator>Ian0706</dc:creator>
      <dc:date>2026-03-30T18:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: Investigations disappearing  in Analyst Queue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Investigations-disappearing-in-Analyst-Queue/m-p/759807#M12879</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/315087"&gt;@Ian0706&lt;/a&gt;&amp;nbsp;No worries. Yes, since we don't have any workarounds published on this one yet.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2026 02:59:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Investigations-disappearing-in-Analyst-Queue/m-p/759807#M12879</guid>
      <dc:creator>kknairr</dc:creator>
      <dc:date>2026-03-31T02:59:39Z</dc:date>
    </item>
  </channel>
</rss>

