Splunk Enterprise Security

No Notables is getting generated however i can get the results when correlation searches are run mannually

saurabhsumangat
New Member

Since morning i am observing my notables are not getting created.
I can see the Notable names in Security posture but once i click on that it doesnt show any results.

when i copy paste the same search on searching and run manually it gives proper results.

What all are the checklist i need to check for this issue?

0 Karma

DavidHourani
Super Champion

Hi @saurabhsumangate,

Is this happening to all your notables ? Or only new ones that you have created ? Also did you check over which time you're running the search ? It could be that you're just on the wrong timeframe.

0 Karma

saurabhsumangat
New Member

Hey David,

This is happening to all the notables which used to generate earlier

0 Karma

DavidHourani
Super Champion

Could be a cookie issue, could you try clearing your browser's cache ?

0 Karma

saurabhsumangat
New Member

This has been resolved automatically.
Do you have any idea, what could be the reason for this behavior?

0 Karma

DavidHourani
Super Champion

it's most probably a browser incompatibility issue.. I've seen it happen with IE and Edge. When results don't show but you know they are there first step should be clearing the cache and logging back in 🙂

0 Karma

saurabhsumangat
New Member

sure.. i ll try it again later

0 Karma

saurabhsumangat
New Member

but my Notable graph in incident review has shown no spikes during a certain interval of time.. is it still related to browser compatibility?

0 Karma

DavidHourani
Super Champion

check the search building the graph, if when you run the search you have nothing at all then that means your correlation searches had stopped, if you do get results it's just a display issue

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...