Alerting

Alert not loading- what does this mean?

So76
Explorer

I am new to splunk. So I got this message that is attached when I click a link

(|loadjob scheduler__hgt2_c3BsdW5rX2ludGVybmFsX21ldHJpY3M__RMD5c1adf444890fb9a1_at_1645171200_579 | head 1 | tail 1)

index=*** sourcetype=***:channel:threats* tag=malware threatInfo.analystVerdict=undefined threatInfo.incidentStatus=unresolved threatInfo.mitigationStatus=mitigated | table _time action dest user signature file_name version description

Saved Search [Detections Handled by SentinelOne]: number of events (1) 

 

I get the attached message.

Can anyone explain how to resolve this?

Labels (1)
0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

hi  @So76 

1. Job that you are trying to access , is still available or expired ? you can check for expiry date from searches, reports and alerts, please find following example screenshot
SanjayReddy_0-1645593835076.png

2. do you have required access to view the data for that report/alert , did you able to view it under search reports alerts?


3. alternately you can directly  access search results of report/alert by  going to search reports alerts

SanjayReddy_4-1645594212629.png
searching the for required alert/report name  and click view recent 

SanjayReddy_2-1645594009922.png

and click on name to view the result

SanjayReddy_0-1645593835076.png

0 Karma

tshah-splunk
Splunk Employee
Splunk Employee

Hey @So76,

You can open the Job inspector and see what exactly is the error and why is the scheduled search results not loading. Open the search.log from the Job Inspector page and search for the "ERROR" keyword. You will be able to identify the reason for not displaying the results.

---
If you find the answer helpful, an upvote/karma is appreciated

So76
Explorer

Was helpful, will escalate with splunk support to fix it

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...