We recently updated from Enterprise Security 7.3.2 to 8.0.4
Correlation searches are not updating the risk index. I can write directly to the risk index, however any "correlation search" (now finding) that is configured to perform risk analysis and has the risk object defined, does not update the risk index.
@DufferDave Please have a look
https://help.splunk.com/en/splunk-enterprise-security-8/user-guide/8.0/analytics/risk-analysis