I'm trying to configure Splunk Enterprise Security but I'm having some issues getting the Incident Review to show anything and I've now realized that it is because my notable index is at 0. out of ~50m events per day I'm sure it's not true that there hasn't been at least 1 notable event.
where do I check to see why these events are not being generated?
Make sure correlation searches are enabled: http://docs.splunk.com/Documentation/ES/5.0.0/Admin/Configurecorrelationsearches#Enable_correlation_...
Make sure correlation searches are enabled: http://docs.splunk.com/Documentation/ES/5.0.0/Admin/Configurecorrelationsearches#Enable_correlation_...
Awesome! I knew I must be over looking something simple. Thank you