- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
splunkreal
Motivator
09-26-2024
02:40 AM
Hello, in clustered environment or standalone,
after upgrading first Splunk core then Splunk ES, incident review not working anymore, not showing any notable.
The macro `notable` is in error and we can see SA-utils python errors in log files.
* If this helps, please upvote or accept solution if it solved *
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
splunkreal
Motivator
09-26-2024
02:41 AM
Solution : upgrading (therefore reinstalling ES) again to ES 7.3.2 solved the issue.
* If this helps, please upvote or accept solution if it solved *
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
splunkreal
Motivator
09-26-2024
02:41 AM
Solution : upgrading (therefore reinstalling ES) again to ES 7.3.2 solved the issue.
* If this helps, please upvote or accept solution if it solved *
