Splunk Enterprise Security

No Notables is getting generated however i can get the results when correlation searches are run mannually

saurabhsumangat
New Member

Since morning i am observing my notables are not getting created.
I can see the Notable names in Security posture but once i click on that it doesnt show any results.

when i copy paste the same search on searching and run manually it gives proper results.

What all are the checklist i need to check for this issue?

0 Karma

DavidHourani
Super Champion

Hi @saurabhsumangate,

Is this happening to all your notables ? Or only new ones that you have created ? Also did you check over which time you're running the search ? It could be that you're just on the wrong timeframe.

0 Karma

saurabhsumangat
New Member

Hey David,

This is happening to all the notables which used to generate earlier

0 Karma

DavidHourani
Super Champion

Could be a cookie issue, could you try clearing your browser's cache ?

0 Karma

saurabhsumangat
New Member

This has been resolved automatically.
Do you have any idea, what could be the reason for this behavior?

0 Karma

DavidHourani
Super Champion

it's most probably a browser incompatibility issue.. I've seen it happen with IE and Edge. When results don't show but you know they are there first step should be clearing the cache and logging back in 🙂

0 Karma

saurabhsumangat
New Member

sure.. i ll try it again later

0 Karma

saurabhsumangat
New Member

but my Notable graph in incident review has shown no spikes during a certain interval of time.. is it still related to browser compatibility?

0 Karma

DavidHourani
Super Champion

check the search building the graph, if when you run the search you have nothing at all then that means your correlation searches had stopped, if you do get results it's just a display issue

0 Karma
Get Updates on the Splunk Community!

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...