Splunk Enterprise Security

Not creating notable event in incident review

vin02
Path Finder

i have created one correlation search and updated the details for the notable event. But my correlation search is not generating the notable event in incident review.
While i am running the correlation query in the search head,it is generating the result.
what are the changes needs to do to get the notable event in the incident review?

neelamsantosh
Path Finder

reload the datamodel.

0 Karma

vin02
Path Finder

How to reload the datamodel without re-starting splunk?

0 Karma

neelamsantosh
Path Finder

Go to
Setting--> data models
select the respective accelerated datamodel and under the dropdown u will find the Acceleration with (Rebuild)

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...