Splunk Enterprise Security

Enterprise Security - Correlation Search - Notable - "default owner" missing users

wgawhh5hbnht
Communicator

I'm attempting to auto-assign users to certain types of Notable events under "Default Owner". For some reason only 20/24 users are showing up as options. The users that are missing from the drop down have accounts with the same role as the other users and they have logged into Enterprise Security before.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...