Getting Data In

Incident Review dashboard has no value

blank
Loves-to-Learn

Incident review dashboard is displaying no value, despite having correlation searches enabled. Upon investigation, I noticed that the notable index has 0 bytes. 

Could someone kindly guide me on how to troubleshoot this issue? Thanks!

Labels (1)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @blank ,

some very stupid questions:

did you enabled Notables as Adaptive Response actions for you Correlation Searches?

are any Correlation Searches triggered?

Ciao.

Giuseppe

0 Karma

blank
Loves-to-Learn

Hi @gcusello 

Yes, I enabled notables as adaptive response actions for my CS. I tried checking the incident review dashboard and run search queries, but the output is 0.

0 Karma
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...