Splunk Enterprise Security

Notable events missing from incident review

itzikshviro
Explorer

Hi guys,
I have an issue with splunk ES, any help would be much appreciated.
The symptoms - some correlation searches (under content management) does not translate to incidents (under incident review).
When i search for the manuali for the events they appear fine.
When i search for the events under index=notable, they also appear. the action that creates notable events is working.
So why is the system doesn't generate incidents for some correlation searches?

Thanks in advance,
Itzik

0 Karma

jeremycarternfc
Engager

I am having this exact same issue. I'm just now starting to investigate but may end up making a support request for it. We're running 7.0.5 and ES 5.0.1.

0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...