Splunk Enterprise Security

Notable Event Status Inconsistency Between List View and Detail View in Mission Control

torgynnurlankul
New Member

I'm experiencing a status synchronization issue in Splunk Enterprise Security 8.3.2 where the notable event status displays differently between the incident list and the detailed event view.

Issue Details:

  • In the Incident Review list, the event shows status as "New"
  • When navigating to the details of the same event, the status displays as "In Progress"
  • This creates confusion regarding the actual current status of the event
    {5A2BBCFA-3678-4809-9CB6-A96D3A5B1BAB}.png
Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @torgynnurlankul 

Had the status changed between loading the Mission Control Analyst Queue screen and clicking on the specific Finding? As far as I understand, the content of the queue/table does not auto-reload when changes are made-  however opening the detail for a finding would load the latest information for it.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

torgynnurlankul
New Member

Thank you for the response. However, this doesn't appear to be a timing/refresh issue in our case.

Additional Details:

  • This inconsistency is affecting approximately 10 notable events simultaneously
  • The status mismatch persists even after manually refreshing the Incident Review page
  • All affected events consistently show "New" in the list view but "In Progress" when accessing the detail view
  • This behavior is reproducible and consistent across multiple page refreshes and different user sessions
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...