Hello,
We have been facing a weird error suddenly, wherein our production Splunk cloud Enterprise Security Incident Review dashboard suddenly isn't showing the Drill down searches in any of the triggered notables. For all of them "Something went wrong" message is thrown up. I tried changing the roles to ess_admin, tried with multiple drilldown searches but none helped. I am wondering if this is an app backend problem, but just wanted to make sure I am not missing out on anything before opening a support ticket. Any help would be greatly appreciated.
I could see that this is a known issue with latest version of ES and already reported in Splunk and they have provided the workaround as well.
Please refer below doc for more info
https://docs.splunk.com/Documentation/ES/7.3.2/RN/KnownIssues