<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Incident Review Incidents Disappear when search completes in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Incident-Review-Incidents-Disappear-when-search-completes/m-p/257374#M189512</link>
    <description>&lt;P&gt;I had possibly a related issue when stumbling upon your post.  In the error console this was logged-&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;incident_review.js:6 Uncaught TypeError: s.replace is not a function
    at Object.getFieldValue (https://prdbsx0005:8443/en-US/static/@e82289930bdd:302/app/SA-ThreatIntelligence/js/pages/incident_review.js:6:2278026)
    at eval (eval at x.template (...
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In my case it turned out to be someone had put a variable substitution in the correlation search name (e.g. $username$) instead of the notable event title.  This was causing the error.&lt;/P&gt;</description>
    <pubDate>Sat, 02 Sep 2017 15:50:47 GMT</pubDate>
    <dc:creator>smeier</dc:creator>
    <dc:date>2017-09-02T15:50:47Z</dc:date>
    <item>
      <title>Incident Review Incidents Disappear when search completes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Incident-Review-Incidents-Disappear-when-search-completes/m-p/257373#M189511</link>
      <description>&lt;P&gt;This is an odd issue. After a restart of Splunk my incident review dashboard will show all of my incidents as long as I filter out high. &lt;/P&gt;

&lt;P&gt;When I initially land on incident review and it does its autorun 24h search I briefly see all of my incidents before they all disappear. It still gives me the option to select all xx incidents so they are there, just not displaying. &lt;/P&gt;

&lt;P&gt;If I filter out the one high event (by greying out the 'high' box) everything displays fine. &lt;/P&gt;

&lt;P&gt;I changed the urgency on the one high to critical and re-ran the search to include the high results as well. Still, everything disappears. &lt;/P&gt;

&lt;P&gt;High seems to be the only thing causing this issue. All other combinations of searches I have tried work fine. Anything that is paired with high aside from high by itself will not display the incidents. &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;UPDATE&lt;/STRONG&gt;&lt;BR /&gt;
2016-03-22 19:22:24,045 ERROR   [56f1fde0097f0d841f4290] utility:49 - name=javascript, class=Splunk.Error, lineNumber=9, message=Uncaught TypeError: Cannot read property 'toString' of undefined, fileName=&lt;A href="https://10.10.10.10:9000/en-US/app/SplunkEnterpriseSecuritySuite/incident_review?form.status_form=*&amp;amp;form.owner_form=*&amp;amp;form.security_domain_form=*&amp;amp;form.rule_name=&amp;amp;form.srch=&amp;amp;earliest=-24h%40h&amp;amp;latest=now&amp;amp;form.new_urgency_count_form="&gt;https://10.10.10.10:9000/en-US/app/SplunkEnterpriseSecuritySuite/incident_review?form.status_form=*&amp;amp;form.owner_form=*&amp;amp;form.security_domain_form=*&amp;amp;form.rule_name=&amp;amp;form.srch=&amp;amp;earliest=-24h%40h&amp;amp;latest=now&amp;amp;form.new_urgency_count_form=&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2016 02:10:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Incident-Review-Incidents-Disappear-when-search-completes/m-p/257373#M189511</guid>
      <dc:creator>miront</dc:creator>
      <dc:date>2016-03-23T02:10:05Z</dc:date>
    </item>
    <item>
      <title>Re: Incident Review Incidents Disappear when search completes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Incident-Review-Incidents-Disappear-when-search-completes/m-p/257374#M189512</link>
      <description>&lt;P&gt;I had possibly a related issue when stumbling upon your post.  In the error console this was logged-&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;incident_review.js:6 Uncaught TypeError: s.replace is not a function
    at Object.getFieldValue (https://prdbsx0005:8443/en-US/static/@e82289930bdd:302/app/SA-ThreatIntelligence/js/pages/incident_review.js:6:2278026)
    at eval (eval at x.template (...
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In my case it turned out to be someone had put a variable substitution in the correlation search name (e.g. $username$) instead of the notable event title.  This was causing the error.&lt;/P&gt;</description>
      <pubDate>Sat, 02 Sep 2017 15:50:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Incident-Review-Incidents-Disappear-when-search-completes/m-p/257374#M189512</guid>
      <dc:creator>smeier</dc:creator>
      <dc:date>2017-09-02T15:50:47Z</dc:date>
    </item>
  </channel>
</rss>

