Splunk Enterprise Security

Error while assigning/ updating notable events.

inayath_khanin
Explorer

Hi Folks,

I am getting below error in the incident review dashboard and this error is persistent impacting operations.

Error: only 0 events successfully updated. unable to edit all selected events due to the max events per bucket limit.

I tried increasing max_events_per_bucket to 2500 referring below link even though the issue is still persistent. 

https://docs.splunk.com/Documentation/ES/6.2.0/Admin/CustomizeIR

Please suggest.

Attached below screenshotCapture.PNG

Thanks in advance

 

haraksin
Path Finder

I am having this issue too - the docs aren't clear about what causes this error, as it's clearly not caused by hitting the event limit, at least not that I can see.

0 Karma

Nisha18789
Builder

Hello @inayath_khanin , you can use a smaller time range when reviewing notable events on Incident Review, which reduces the number of events on the Incident Review dashboard to less than 1000. 1000 is the default value of max_events_per_bucket 

for more details refer splunk documentation:

https://docs.splunk.com/Documentation/ES/6.2.0/Admin/CustomizeIR

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...