Splunk Enterprise Security

Incident Review not showing the notable events.

vinayakwagh
Engager

I have one correlation search which runs every 15 mins I have events for same in the index "notable" but the same notable events are not visible under the incident review tab any suggestion?

0 Karma

lakshman239
Influencer

Do you have required permissions/capabilities (e.g. ess_analyst role)? Is your admin or others in the team able to view the notable in the Incident review screen?

https://docs.splunk.com/Documentation/ES/5.3.0/Install/ConfigureUsersRoles

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...