We just upgraded from Enterprise Security 6.4.x to 6.6.2. In version 6.4, we were able to run real-time searches, pause the search grab and work the notable. We upgraded to 6.6.2 and now that feature no longer exists. I don't see an auto refresh option on version 6.6.2, so my question is how can I get the Incident Review dashboard to auto refresh so we don't have to do it manually?
Thanks in advance.
Scott
Hi,
I found a workaround to auto-refresh Incident Review dashboard by adding these 3 lines below to this html file as it is already included in Incident Review dashboard xml file.
/opt/splunk/etc/apps/SA-ThreatIntelligence/appserver/templates/generic.html
<head>
<meta http-equiv="refresh" content="300">
</head>
This will refresh the page after 300 seconds (5 mins).
<%inherit file="base.html"/>
<head>
<meta http-equiv="refresh" content="300">
</head>
<div class="preload">
<div id="placeholder-splunk-bar">
<a href="${make_url([])}" class="brand" title="splunk > listen to your data">splunk<strong>></strong></a>
</div>
<div id="placeholder-app-bar"></div>
<div id="placeholder-main-section-body">
${_('Loading...')}
</div>
</div>
Please let me know for any further details, and accept the answer if it solved the problem.
Ahmed