Good day,

I have noticed that the incident review shows no events, for about a day.

The indexers were reviewed by means of a search and if records are observed.

Do you know what it could be?

I appreciate your help.

Splunk Employee
Does "index=notable" show results?  If so does the search `notable` show results?  If so are you using notable event suppressions?


If index=notable does not show data, then it sounds like you did not generate notable events

At the end of the day, index=notable feed IR page.  And Correlation searches feed index=notable

Hello, the causes can be many, you must provide a little more information to try to help you

For example, at the top there are some warnings, be it a warning or error message



Super Champion

can you check if you had any problems with search head kvstore.

