I use the inbuilt ES notables and incidents for creating the tickets for team to work on the issues. All the tickets are saved in separate index=notable, however the issue is that the drill down events of these notables are not saved separately. Drill down search runs on normal indexes such as windows/unix etc with shorter retention periods. Sometimes, I need those drill down events for research purpose, then i need to unfreeze the whole bucket to get one event of appropriate data.
I want to create a new index which will store drill down events for all the notables raised automatically and then I can adjust its retention period as per my need.
Kindly advise.
Thanks for the explanations.
Drilldowns are created when the CS is created, but they don't run until a user clicks on an event. That's because the drilldown often uses values from the clicked event in its search. To have a CS save all possible drilldown events would be the same as saving the data it just searched. Since a CS may search the same data many times over the course of a day, re-saving every event searched would be very wasteful.
Would an auditor be satisfied if asked to wait a few hours for the archived bucket to be restored?
Consider making a case for different behavior at https://ideas.splunk.com
Submitted the idea. Kindly upvote.
How do you know what events are needed for a drilldown before the drilldown is clicked?
Why retain a notable event longer than the supporting events? If the notable can't be investigated then there's little point in keeping it.