Splunk Enterprise Security

Notable events missing from incident review

itzikshviro
Explorer

Hi guys,
I have an issue with splunk ES, any help would be much appreciated.
The symptoms - some correlation searches (under content management) does not translate to incidents (under incident review).
When i search for the manuali for the events they appear fine.
When i search for the events under index=notable, they also appear. the action that creates notable events is working.
So why is the system doesn't generate incidents for some correlation searches?

Thanks in advance,
Itzik

0 Karma

jeremycarternfc
Engager

I am having this exact same issue. I'm just now starting to investigate but may end up making a support request for it. We're running 7.0.5 and ES 5.0.1.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...