Splunk Enterprise Security

Incident Review dashboard drilldown search not working

splunkerarijit
New Member

Hello,

We have been facing a weird error suddenly, wherein our production Splunk cloud Enterprise Security Incident Review dashboard suddenly isn't showing the Drill down searches in any of the triggered notables. For all of them "Something went wrong" message is thrown up. I tried changing the roles to ess_admin, tried with multiple drilldown searches but none helped. I am wondering if this is an app backend problem, but just wanted to make sure I am not missing out on anything before opening a support ticket. Any help would be greatly appreciated.

error.png

Labels (2)
0 Karma

Bhumi
Explorer

Hi @splunkerarijit 

I could see that  this is a known issue with latest version of ES and already reported in Splunk and they have provided the workaround as well.

Please refer below doc for more info

https://docs.splunk.com/Documentation/ES/7.3.2/RN/KnownIssues


 If this helps, please upvote or accept solution if it solved
0 Karma
Get Updates on the Splunk Community!

Announcing the Expansion of the Splunk Academic Alliance Program

The Splunk Community is more than just an online forum — it’s a network of passionate users, administrators, ...

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...