Splunk Enterprise Security

Help with ESS Incident Review "There was an error fetching related investigations"

dood9999
Explorer

Having issues with fetching investigations in incident review.

Investigation is added for the alert but when accessing the alert I get the error "There was an error fetching related investigations" under related investigations.

My assumption is that it is a permissions issue since admins are able to view it with no problems.

However it appears that all the permissions that are needed are in place.

Any help is greatly appreciated.


Follow up question - Is there a way to auto add notables to investigations that share the same artifacts?

Labels (3)
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...