Splunk Enterprise Security

Notable events stopped updating in Incidnet Review in ES app

kiranp2
New Member

Hi Splunkers,

we are not able to see any notable events from yesterday in ES app even though we have not made changes to the configurations.

I have checked the scheduler.log file and there is no information about the running of correlation rules from yesterday where as i can see next schedule run time in splunk console. And also i have checked the splunkd.log i couldn't find any trace.

Does anyone of you have faced the same situation? Can you please someone help us on this how to process further .

Thanks
Pench

0 Karma

maciep
Champion

So are you still not seeing any notables or did this just happen over yesterday?

Nonetheless, you should open a splunk support case for this, because troubleshooting it over a forum won't very efficient. And if ES just stopped working, that sounds like something support should hear about.

Other than that, maybe start looking for errors/issues sometime around the last notable you saw. And of course if this is still an issue, try restarting splunk (but I'm sure you've tried that)

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...