Splunk Enterprise Security

Not creating notable event in incident review

vin02
Path Finder

i have created one correlation search and updated the details for the notable event. But my correlation search is not generating the notable event in incident review.
While i am running the correlation query in the search head,it is generating the result.
what are the changes needs to do to get the notable event in the incident review?

neelamsantosh
Path Finder

reload the datamodel.

0 Karma

vin02
Path Finder

How to reload the datamodel without re-starting splunk?

0 Karma

neelamsantosh
Path Finder

Go to
Setting--> data models
select the respective accelerated datamodel and under the dropdown u will find the Acceleration with (Rebuild)

0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...