Splunk Enterprise Security

Help with ESS Incident Review "There was an error fetching related investigations"

dood9999
Explorer

Having issues with fetching investigations in incident review.

Investigation is added for the alert but when accessing the alert I get the error "There was an error fetching related investigations" under related investigations.

My assumption is that it is a permissions issue since admins are able to view it with no problems.

However it appears that all the permissions that are needed are in place.

Any help is greatly appreciated.


Follow up question - Is there a way to auto add notables to investigations that share the same artifacts?

Labels (3)
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...