Splunk Enterprise Security
Highlighted

Not creating notable event in incident review

Path Finder

i have created one correlation search and updated the details for the notable event. But my correlation search is not generating the notable event in incident review.
While i am running the correlation query in the search head,it is generating the result.
what are the changes needs to do to get the notable event in the incident review?

Highlighted

Re: Not creating notable event in incident review

Path Finder

reload the datamodel.

0 Karma
Highlighted

Re: Not creating notable event in incident review

Path Finder

How to reload the datamodel without re-starting splunk?

0 Karma
Highlighted

Re: Not creating notable event in incident review

Path Finder

Go to
Setting--> data models
select the respective accelerated datamodel and under the dropdown u will find the Acceleration with (Rebuild)

0 Karma