Splunk Enterprise Security

Notable events missing from incident review

itzikshviro
Explorer

Hi guys,
I have an issue with splunk ES, any help would be much appreciated.
The symptoms - some correlation searches (under content management) does not translate to incidents (under incident review).
When i search for the manuali for the events they appear fine.
When i search for the events under index=notable, they also appear. the action that creates notable events is working.
So why is the system doesn't generate incidents for some correlation searches?

Thanks in advance,
Itzik

0 Karma

jeremycarternfc
Engager

I am having this exact same issue. I'm just now starting to investigate but may end up making a support request for it. We're running 7.0.5 and ES 5.0.1.

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...