Splunk Enterprise Security

Help with ESS Incident Review "There was an error fetching related investigations"

dood9999
Engager

Having issues with fetching investigations in incident review.

Investigation is added for the alert but when accessing the alert I get the error "There was an error fetching related investigations" under related investigations.

My assumption is that it is a permissions issue since admins are able to view it with no problems.

However it appears that all the permissions that are needed are in place.

Any help is greatly appreciated.


Follow up question - Is there a way to auto add notables to investigations that share the same artifacts?

0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...