<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Notable event missing from Incident Review dashboard? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Notable-event-missing-from-Incident-Review-dashboard/m-p/413263#M4911</link>
    <description>&lt;P&gt;I have a search in which is generating results when I have it set as an alert and is successfully creating and event in the notable index. However, when I look on the Incident Review dashboard it does not show. I have multiple other searches/alerts which are working without any issues. Has anyone experienced this or been able to resolve this? I've tried rebuilding the search/alert, but am still having the same issue (notable event is generated, but does not show in the Incident Review dashboard).&lt;/P&gt;</description>
    <pubDate>Fri, 18 Jan 2019 15:11:38 GMT</pubDate>
    <dc:creator>arlombar</dc:creator>
    <dc:date>2019-01-18T15:11:38Z</dc:date>
    <item>
      <title>Notable event missing from Incident Review dashboard?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Notable-event-missing-from-Incident-Review-dashboard/m-p/413263#M4911</link>
      <description>&lt;P&gt;I have a search in which is generating results when I have it set as an alert and is successfully creating and event in the notable index. However, when I look on the Incident Review dashboard it does not show. I have multiple other searches/alerts which are working without any issues. Has anyone experienced this or been able to resolve this? I've tried rebuilding the search/alert, but am still having the same issue (notable event is generated, but does not show in the Incident Review dashboard).&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 15:11:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Notable-event-missing-from-Incident-Review-dashboard/m-p/413263#M4911</guid>
      <dc:creator>arlombar</dc:creator>
      <dc:date>2019-01-18T15:11:38Z</dc:date>
    </item>
    <item>
      <title>Re: Notable event missing from Incident Review dashboard?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Notable-event-missing-from-Incident-Review-dashboard/m-p/413264#M4912</link>
      <description>&lt;P&gt;Can you share your correlation search (after masking sensitive data)?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2019 22:13:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Notable-event-missing-from-Incident-Review-dashboard/m-p/413264#M4912</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-01-28T22:13:54Z</dc:date>
    </item>
    <item>
      <title>Re: Notable event missing from Incident Review dashboard?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Notable-event-missing-from-Incident-Review-dashboard/m-p/413265#M4913</link>
      <description>&lt;P&gt;Run you MC Health Checks and see if you have any &lt;CODE&gt;Skipped Searches&lt;/CODE&gt; (I assume that you will find that you do).  You can also use the &lt;CODE&gt;ES Health Check&lt;/CODE&gt; app for this.  It is possible that the search that populates the dashboard from what ends up in the notable index is not being run because of too much load (skipped searches).  As a test (and a temporary work-around until you can fix the skipped-searches problem), you can manually run the &lt;CODE&gt;ESS - Notable Events&lt;/CODE&gt;.  It is safe to run this at any time and it will update the &lt;CODE&gt;Security Posture&lt;/CODE&gt; dashaboard to the latest notables state.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2019 23:33:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Notable-event-missing-from-Incident-Review-dashboard/m-p/413265#M4913</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-28T23:33:33Z</dc:date>
    </item>
    <item>
      <title>Re: Notable event missing from Incident Review dashboard?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Notable-event-missing-from-Incident-Review-dashboard/m-p/413266#M4914</link>
      <description>&lt;P&gt;Sorry for my late reply, thanks for your suggestions. Could you explain how I would run "ESS - Notable Events"? Is this a built in search or something in the UI? I know how to look at the index in a search, but just wanted to be clear what you are advising to do as the work around.  Also, I ran a health check on the MC and the only issue that came back was for a skipped search, but when I drilled down to see what search was being skipped, it was unrelated to the one I am having an issue with.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 17:27:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Notable-event-missing-from-Incident-Review-dashboard/m-p/413266#M4914</guid>
      <dc:creator>arlombar</dc:creator>
      <dc:date>2019-02-06T17:27:08Z</dc:date>
    </item>
    <item>
      <title>Re: Notable event missing from Incident Review dashboard?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Notable-event-missing-from-Incident-Review-dashboard/m-p/413267#M4915</link>
      <description>&lt;P&gt;Go to &lt;CODE&gt;Settings&lt;/CODE&gt; -&amp;gt; &lt;CODE&gt;Searches, reports, and alerts&lt;/CODE&gt; and search for &lt;CODE&gt;ESS - Notable Events&lt;/CODE&gt;.  Then click &lt;CODE&gt;Run&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 18:18:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Notable-event-missing-from-Incident-Review-dashboard/m-p/413267#M4915</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-02-08T18:18:08Z</dc:date>
    </item>
  </channel>
</rss>

