<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Notable Events index empty in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Notable-Events-index-empty/m-p/340902#M3222</link>
    <description>&lt;P&gt;Awesome! I knew I must be over looking something simple. Thank you&lt;/P&gt;</description>
    <pubDate>Thu, 19 Apr 2018 12:47:18 GMT</pubDate>
    <dc:creator>travislange</dc:creator>
    <dc:date>2018-04-19T12:47:18Z</dc:date>
    <item>
      <title>Notable Events index empty</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Notable-Events-index-empty/m-p/340900#M3220</link>
      <description>&lt;P&gt;I'm trying to configure Splunk Enterprise Security but I'm having some issues getting the Incident Review to show anything and I've now realized that it is because my notable index is at 0. out of ~50m events per day I'm sure it's not true that there hasn't been at least 1 notable event. &lt;/P&gt;

&lt;P&gt;where do I check to see why these events are not being generated?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2018 13:37:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Notable-Events-index-empty/m-p/340900#M3220</guid>
      <dc:creator>travislange</dc:creator>
      <dc:date>2018-04-18T13:37:50Z</dc:date>
    </item>
    <item>
      <title>Re: Notable Events index empty</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Notable-Events-index-empty/m-p/340901#M3221</link>
      <description>&lt;P&gt;Make sure correlation searches are enabled: &lt;A href="http://docs.splunk.com/Documentation/ES/5.0.0/Admin/Configurecorrelationsearches#Enable_correlation_searches"&gt;http://docs.splunk.com/Documentation/ES/5.0.0/Admin/Configurecorrelationsearches#Enable_correlation_searches&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2018 16:23:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Notable-Events-index-empty/m-p/340901#M3221</guid>
      <dc:creator>smoir_splunk</dc:creator>
      <dc:date>2018-04-18T16:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: Notable Events index empty</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Notable-Events-index-empty/m-p/340902#M3222</link>
      <description>&lt;P&gt;Awesome! I knew I must be over looking something simple. Thank you&lt;/P&gt;</description>
      <pubDate>Thu, 19 Apr 2018 12:47:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Notable-Events-index-empty/m-p/340902#M3222</guid>
      <dc:creator>travislange</dc:creator>
      <dc:date>2018-04-19T12:47:18Z</dc:date>
    </item>
  </channel>
</rss>

