Hello, in clustered environment or standalone,
after upgrading first Splunk core then Splunk ES, incident review not working anymore, not showing any notable.
The macro `notable` is in error and we can see SA-utils python errors in log files.
Solution : upgrading (therefore reinstalling ES) again to ES 7.3.2 solved the issue.
Solution : upgrading (therefore reinstalling ES) again to ES 7.3.2 solved the issue.