Splunk Enterprise Security

Enterprise Security: why the incidents don't show up in the lookup?

danielbb
Motivator

With all the help from @solarboyz1, the correlation searches produce now notable events, which show up in the Incident Review page.

index=notable shows them but | inputlookup incident_review_lookup shows zero results.

Why is that?

Tags (1)
0 Karma
1 Solution

solarboyz1
Builder

The state and ownership information are stored in the incident_review_lookup

Until an action is taken on the notable, I don't believe anything will stored for it in incident_review_lookup

http://dev.splunk.com/view/enterprise-security/SP-CAAAFA9

View solution in original post

jawaharas
Motivator

Once you assign the notable event/incident to an user, you can notice records in incident_review_lookupfile.

danielbb
Motivator

Right, just saw it running and | inputlookup incident_review_lookup shows the assigned incident.

0 Karma

solarboyz1
Builder

The state and ownership information are stored in the incident_review_lookup

Until an action is taken on the notable, I don't believe anything will stored for it in incident_review_lookup

http://dev.splunk.com/view/enterprise-security/SP-CAAAFA9

First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...