Splunk Enterprise Security

Enterprise Security Correlation Searches are not updating the risk index

DufferDave
Engager

We recently updated from Enterprise Security 7.3.2 to 8.0.4     

Correlation searches are not updating the risk index.  I can write directly to the risk index, however any "correlation search" (now finding) that is configured to perform risk analysis and has the risk object defined, does not update the risk index.

 

 

Labels (1)
0 Karma

kiran_panchavat
Champion

@DufferDave  Please have a look 

https://lantern.splunk.com/Security/Product_Tips/Enterprise_Security/Installing_and_upgrading_to_Spl... 

https://help.splunk.com/en/splunk-enterprise-security-8/user-guide/8.0/analytics/risk-analysis 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...