Splunk Enterprise Security

How to troubleshoot notable events not generating / not showing under Incident Review?

natemax
New Member

Splunk Enterprise v7.0.1

Some notable events are showing in Incident Review but not all.

We are missing some notables that used to show/generate fine in the past.

Not sure if related but running MC Health Check shows the following -

  1. Orphaned scheduled searches Splunk Miscellaneous configuration, search

    One or more scheduled searches are orphaned, meaning that they are no longer associated with valid owners. The scheduler will not run orphaned scheduled searches.

  2. Search scheduler skip ratio Data Search scheduler

    Scheduled searches are being skipped on one or more search heads.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The MC Health Check explained why you are missing notable events.

  1. You have orphaned scheduled searches, which won't run. Scheduled/correlation searches that don't run don't produce notables. Assign the searches to another user.
  2. Skipped searches don't run and, therefore, don't product notables. Find out why the searches were skipped and make the necessary corrections.
---
If this reply helps you, Karma would be appreciated.
0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...