Splunk Enterprise Security

Enterprise Security: why don't the events get indexed to the notable index?

danielbb
Motivator

This one is, in a sense, a continuation of Enterprise Security: How can I trace the notable events?

Running - index=_internal component=SavedSplunker status=success sourcetype=scheduler indextime2 result_count>0 suppressed=0 app=SplunkEnterpriseSecuritySuite for the past 24 hours and I get 10 events.

However, index=notable returns 0 events and I verified that the notable index exists.

0 Karma
1 Solution

Vijeta
Influencer

@danielbb Was there any event that would satisfy the correlation searches and would trigger notable event? The query you posted just shows the scheduled jobs running on ES , it doesn't mean that there was a condition met for notable events in correleation searches.
Also make sure you have sufficient permissions to access notable index.

View solution in original post

Vijeta
Influencer

@danielbb Was there any event that would satisfy the correlation searches and would trigger notable event? The query you posted just shows the scheduled jobs running on ES , it doesn't mean that there was a condition met for notable events in correleation searches.
Also make sure you have sufficient permissions to access notable index.

danielbb
Motivator

@solarboyz1 explained in the "parent" thread, if I understand it correctly, that a notable event should be produced.

I do have access to this index...

0 Karma

Vijeta
Influencer

@danielbb Sorry I didn't know there was a parent thread. Yes that's correct a notable event or Indicator of Compromise should be produced in order to populate notable index. You can create a test correlation search and test it with any event , just to check . Any event in . notable index would update the Security Posture Dashboard and Incident Review dashboard.

0 Karma

danielbb
Motivator

Great. I just updated the parent one and alert_actions is actually empty in my case.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...