Splunk Enterprise Security

ES: incident Review is not showing as expected

neelamsantosh
Path Finder

Our incident Review board has different view and not functioning as expected due to which we are unable to filter from the dropdown list

Chrome: up to date (Version 57.0.2987.133 (64-bit))
Splunk Enterprise : 6.5.2
Splunk ES: 4.1
alt text

0 Karma

neelamsantosh
Path Finder

I believe this is known issue SOLNESS-10915. Enterprise Security 4.1 is
not compatible with version 6.5.x of Splunk. It is recommended to upgrade
your Enterprise Security as the workaround for this issue.

http://docs.splunk.com/Documentation/ES/4.1.1/RN/KnownIssues

0 Karma

hardikJsheth
Motivator

I agree with @smoir.

In case you are upgrading from earlier version of ES try to reload the IR page after clearing cache of your browser.

0 Karma

smoir_splunk
Splunk Employee
Splunk Employee

Hello @neelamsantosh,

Make sure you are using a compatible version of Splunk Enterprise with Splunk Enterprise Security.

Check this table for your version of Enterprise Security: http://docs.splunk.com/Documentation/ES/4.6.0/Install/DeploymentPlanning#Splunk_Enterprise_system_re...

Thanks,
Sarah

0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...