Splunk Enterprise Security

Incident Review not showing the notable events.

vinayakwagh
Explorer

I have one correlation search which runs every 15 mins I have events for same in the index "notable" but the same notable events are not visible under the incident review tab any suggestion?

0 Karma

lakshman239
Influencer

Do you have required permissions/capabilities (e.g. ess_analyst role)? Is your admin or others in the team able to view the notable in the Incident review screen?

https://docs.splunk.com/Documentation/ES/5.3.0/Install/ConfigureUsersRoles

0 Karma
Get Updates on the Splunk Community!

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...

AppDynamics is now part of Splunk Ideas

Hello Splunkers, We have exciting news for you! AppDynamics has been added to the Splunk Ideas Portal. Which ...

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...