Splunk Enterprise Security

Incident Review dashboard drilldown search not working

splunkerarijit
New Member

Hello,

We have been facing a weird error suddenly, wherein our production Splunk cloud Enterprise Security Incident Review dashboard suddenly isn't showing the Drill down searches in any of the triggered notables. For all of them "Something went wrong" message is thrown up. I tried changing the roles to ess_admin, tried with multiple drilldown searches but none helped. I am wondering if this is an app backend problem, but just wanted to make sure I am not missing out on anything before opening a support ticket. Any help would be greatly appreciated.

error.png

Labels (2)
0 Karma

Bhumi
Explorer

Hi @splunkerarijit 

I could see that  this is a known issue with latest version of ES and already reported in Splunk and they have provided the workaround as well.

Please refer below doc for more info

https://docs.splunk.com/Documentation/ES/7.3.2/RN/KnownIssues


 If this helps, please upvote or accept solution if it solved
0 Karma
Get Updates on the Splunk Community!

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

AI Adoption Hub Launch | Curated Resources to Get Started with AI in Splunk

Hey Splunk Practitioners and AI Enthusiasts! It’s no secret (or surprise) that AI is at the forefront of ...