Splunk Enterprise Security

Splunk ES 8.0.2 missing drill down

muhammadfahimma
Explorer

After a recent upgrade to Splunk ES 8.0.2, we have observed that none of the drill downs for detection based searches are available in the mission control screen anymore. Don't see any errors that might hint any abnormality. Has anyone come across a similar issue? How can this issue be debugged?

Labels (1)
0 Karma

livehybrid
Champion

Hi @muhammadfahimma 

I believe you may be experiencing a bug (BLUERIDGE-13575) which is a known issue with ES 8.0.2 (See https://docs.splunk.com/Documentation/ES/8.0.2/RN/KnownIssues)

If this is the issue then you may find the following workaround solves the issue until fixed in the product:

Workaround:
Remove `source` before sending to detection.
add `| fields - source` to end of search

Either way, I would suggest raising a support case, as even if it is this particular bug they will be able to associate it to your account and keep you updated with progress and resolution.

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

muhammadfahimma
Explorer

I don't think that is the case, the drilldowns are not appearing at all

0 Karma

livehybrid
Champion

In that case @muhammadfahimma  I think it is best to get this raised with Splunk Support, they should let you know the reference number once it has been logged and you can track it on the Release Notes (https://docs.splunk.com/Documentation/ES/latest/RN/NewFeatures) page.

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

0 Karma

muhammadfahimma
Explorer

thank you @livehybrid  i ended up creating a ticket with splunk support

kiran_panchavat
Influencer

@muhammadfahimma 

Please review the following, and I kindly request you to raise a Splunk support ticket.

Investigate findings using drilldown searches and dashboards in Splunk Enterprise Security - Splunk ...

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

muhammadfahimma
Explorer

I'm following the same steps, but don't see the drill down appearing

0 Karma
Get Updates on the Splunk Community!

Uncovering Multi-Account Fraud with Splunk Banking Analytics

Last month, I met with a Senior Fraud Analyst at a nationally recognized bank to discuss their recent success ...

Secure Your Future: A Deep Dive into the Compliance and Security Enhancements for the ...

What has been announced?  In the blog, “Preparing your Splunk Environment for OpensSSL3,”we announced the ...

New This Month in Splunk Observability Cloud - Synthetic Monitoring updates, UI ...

This month, we’re delivering several platform, infrastructure, application and digital experience monitoring ...