- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Notable events aren't shown in Incident Review
kanam
Loves-to-Learn Everything
10-05-2020
02:28 AM
I created correlation search and add Notable action as "Adaptive Response Actions".
By running search there are some events and actually Activity>Jobs shows events are existing.
However "Incident Review" doesn't display any event.
#I configure "Throttling" disable by setting "Window duration" as "0".
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
lkutch_splunk

Splunk Employee
12-22-2020
03:34 PM
Hi,
There's a new page in the docs about troubleshooting missing notable events in Splunk Enterprise Security. Maybe one of these tips will help:
https://docs.splunk.com/Documentation/ES/6.4.0/Admin/Troubleshootnotables
