<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why do we get errors on the REST command in the Investigation Overview dashboard on Splunk ES? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-do-we-get-errors-on-the-REST-command-in-the-Investigation/m-p/470952#M7214</link>
    <description>&lt;P&gt;We tried fixing the problem by deleting all investigations older than a certain date. This "solved" the problem for a time, but now the problem has reappeared. Again we can use the REST commando to look for investigations older than a certain date. We can't figure out why. It seems like a bug to us.&lt;/P&gt;</description>
    <pubDate>Thu, 06 Feb 2020 08:54:05 GMT</pubDate>
    <dc:creator>hettervik</dc:creator>
    <dc:date>2020-02-06T08:54:05Z</dc:date>
    <item>
      <title>Why do we get errors on the REST command in the Investigation Overview dashboard on Splunk ES?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-do-we-get-errors-on-the-REST-command-in-the-Investigation/m-p/470951#M7213</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;After upgrading to Splunk ES version 6.0.0 we got the &lt;A href="https://docs.splunk.com/Documentation/ES/6.0.0/User/Audit#Investigation_Overview"&gt;Investigation Overview&lt;/A&gt; dashboard, but we have some problems when running it. If we try to look for investigations far back in time, the searches on the dashboard doesn't work, and they give an error. More specifically, the search  &lt;CODE&gt;| rest splunk_server=local count=0 /services/storage/investigation/investigation all=true earliest="-90d@d" latest="now"&lt;/CODE&gt; gives the error  &lt;CODE&gt;Failed to fetch REST endpoint uri=https://127.0.0.1:8089/services/storage/investigation/investigation [...] from server &lt;A href="https://127.0.0.1:8089" target="test_blank"&gt;https://127.0.0.1:8089&lt;/A&gt; [...]&lt;/CODE&gt;. &lt;STRONG&gt;Note, it works fine if we are not looking that far back, it only throws an error if we look for investigations older than a certain time.&lt;/STRONG&gt; We don't know if it's the amount of time looking back itself, or if it is a certain investigation that causes the REST call to crash, but either way this looks like a bug to me.&lt;/P&gt;

&lt;P&gt;Anyone else have experienced the same issue, or possible have a fix?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2019 13:57:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-do-we-get-errors-on-the-REST-command-in-the-Investigation/m-p/470951#M7213</guid>
      <dc:creator>hettervik</dc:creator>
      <dc:date>2019-12-19T13:57:50Z</dc:date>
    </item>
    <item>
      <title>Re: Why do we get errors on the REST command in the Investigation Overview dashboard on Splunk ES?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-do-we-get-errors-on-the-REST-command-in-the-Investigation/m-p/470952#M7214</link>
      <description>&lt;P&gt;We tried fixing the problem by deleting all investigations older than a certain date. This "solved" the problem for a time, but now the problem has reappeared. Again we can use the REST commando to look for investigations older than a certain date. We can't figure out why. It seems like a bug to us.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 08:54:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-do-we-get-errors-on-the-REST-command-in-the-Investigation/m-p/470952#M7214</guid>
      <dc:creator>hettervik</dc:creator>
      <dc:date>2020-02-06T08:54:05Z</dc:date>
    </item>
    <item>
      <title>Re: Why do we get errors on the REST command in the Investigation Overview dashboard on Splunk ES?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-do-we-get-errors-on-the-REST-command-in-the-Investigation/m-p/549185#M9896</link>
      <description>&lt;P&gt;Having the same problem, we can walk right up to 7 days then it starts bricking, it seemed to work fine right out of the box, at first then I think once we broke 7 days age it went away; 6.0.1&lt;/P&gt;&lt;P&gt;variations trying to inspect:&lt;/P&gt;&lt;P&gt;| `investigations` all=true earliest="-8d" latest="now"&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Failed to fetch REST endpoint uri=&lt;A href="https://127.0.0.1:8089/services/storage/investigation/investigation?count=0&amp;amp;all=true&amp;amp;earliest=-8d&amp;amp;latest=now" target="_blank"&gt;https://127.0.0.1:8089/services/storage/investigation/investigation?count=0&amp;amp;all=true&amp;amp;earliest=-8d&amp;amp;latest=now&lt;/A&gt; from server &lt;A href="https://127.0.0.1:8089" target="_blank"&gt;https://127.0.0.1:8089&lt;/A&gt;. Check that the URI path provided exists in the REST API.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 20:32:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-do-we-get-errors-on-the-REST-command-in-the-Investigation/m-p/549185#M9896</guid>
      <dc:creator>GDustin</dc:creator>
      <dc:date>2021-04-23T20:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why do we get errors on the REST command in the Investigation Overview dashboard on Splunk ES?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-do-we-get-errors-on-the-REST-command-in-the-Investigation/m-p/625866#M11234</link>
      <description>&lt;P&gt;Hi stuck on the same issue here..&lt;/P&gt;&lt;P&gt;works fine for specific time but when we go far from 50 days~ it breaks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any help?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2023 16:43:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-do-we-get-errors-on-the-REST-command-in-the-Investigation/m-p/625866#M11234</guid>
      <dc:creator>xori22</dc:creator>
      <dc:date>2023-01-04T16:43:04Z</dc:date>
    </item>
  </channel>
</rss>

