<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to troubleshoot notable events not generating / not showing under Incident Review? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-troubleshoot-notable-events-not-generating-not-showing/m-p/466711#M6983</link>
    <description>&lt;P&gt;Splunk Enterprise v7.0.1&lt;/P&gt;

&lt;P&gt;Some notable events are showing in Incident Review but not all. &lt;/P&gt;

&lt;P&gt;We are missing some notables that used to show/generate fine in the past. &lt;/P&gt;

&lt;P&gt;Not sure if related but running MC Health Check shows the following - &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;Orphaned scheduled searches  Splunk Miscellaneous    configuration, search&lt;BR /&gt;&lt;BR /&gt;
One or more scheduled searches are orphaned, meaning that they are no longer associated with valid owners. The scheduler will not run orphaned scheduled searches.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Search scheduler skip ratio  Data Search scheduler&lt;BR /&gt;&lt;BR /&gt;
Scheduled searches are being skipped on one or more search heads.&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
    <pubDate>Tue, 17 Dec 2019 16:47:12 GMT</pubDate>
    <dc:creator>natemax</dc:creator>
    <dc:date>2019-12-17T16:47:12Z</dc:date>
    <item>
      <title>How to troubleshoot notable events not generating / not showing under Incident Review?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-troubleshoot-notable-events-not-generating-not-showing/m-p/466711#M6983</link>
      <description>&lt;P&gt;Splunk Enterprise v7.0.1&lt;/P&gt;

&lt;P&gt;Some notable events are showing in Incident Review but not all. &lt;/P&gt;

&lt;P&gt;We are missing some notables that used to show/generate fine in the past. &lt;/P&gt;

&lt;P&gt;Not sure if related but running MC Health Check shows the following - &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;Orphaned scheduled searches  Splunk Miscellaneous    configuration, search&lt;BR /&gt;&lt;BR /&gt;
One or more scheduled searches are orphaned, meaning that they are no longer associated with valid owners. The scheduler will not run orphaned scheduled searches.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Search scheduler skip ratio  Data Search scheduler&lt;BR /&gt;&lt;BR /&gt;
Scheduled searches are being skipped on one or more search heads.&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Tue, 17 Dec 2019 16:47:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-troubleshoot-notable-events-not-generating-not-showing/m-p/466711#M6983</guid>
      <dc:creator>natemax</dc:creator>
      <dc:date>2019-12-17T16:47:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot notable events not generating / not showing under Incident Review?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-troubleshoot-notable-events-not-generating-not-showing/m-p/466712#M6984</link>
      <description>&lt;P&gt;The MC Health Check explained why you are missing notable events.  &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;You have orphaned scheduled searches, which won't run.  Scheduled/correlation searches that don't run don't produce notables.  Assign the searches to another user.&lt;/LI&gt;
&lt;LI&gt;Skipped searches don't run and, therefore, don't product notables.  Find out why the searches were skipped and make the necessary corrections.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Tue, 17 Dec 2019 18:44:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-troubleshoot-notable-events-not-generating-not-showing/m-p/466712#M6984</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-12-17T18:44:38Z</dc:date>
    </item>
  </channel>
</rss>

