Splunk Enterprise Security

No Notables is getting generated however i can get the results when correlation searches are run mannually

saurabhsumangat
New Member

Since morning i am observing my notables are not getting created.
I can see the Notable names in Security posture but once i click on that it doesnt show any results.

when i copy paste the same search on searching and run manually it gives proper results.

What all are the checklist i need to check for this issue?

0 Karma

DavidHourani
Super Champion

Hi @saurabhsumangate,

Is this happening to all your notables ? Or only new ones that you have created ? Also did you check over which time you're running the search ? It could be that you're just on the wrong timeframe.

0 Karma

saurabhsumangat
New Member

Hey David,

This is happening to all the notables which used to generate earlier

0 Karma

DavidHourani
Super Champion

Could be a cookie issue, could you try clearing your browser's cache ?

0 Karma

saurabhsumangat
New Member

This has been resolved automatically.
Do you have any idea, what could be the reason for this behavior?

0 Karma

DavidHourani
Super Champion

it's most probably a browser incompatibility issue.. I've seen it happen with IE and Edge. When results don't show but you know they are there first step should be clearing the cache and logging back in 🙂

0 Karma

saurabhsumangat
New Member

sure.. i ll try it again later

0 Karma

saurabhsumangat
New Member

but my Notable graph in incident review has shown no spikes during a certain interval of time.. is it still related to browser compatibility?

0 Karma

DavidHourani
Super Champion

check the search building the graph, if when you run the search you have nothing at all then that means your correlation searches had stopped, if you do get results it's just a display issue

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...