Splunk Enterprise Security

Search by id does not work in Incident Review

rbenbenish
New Member

When running a search on the Incident Review dashboard where the search term is the <event_id> value or event_id="<event_id>", there are no results.
It used to work in the past, and in one of the last updates, it stopped working.
I am using Enterprise Security version 7.3.2

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...

New Dates, New City: Save the Date for .conf25!

Wake up, babe! New .conf25 dates AND location just dropped!! That's right, this year, .conf25 is taking place ...

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...