Splunk Enterprise Security

Splunk ES 8.0.2 missing drill down

muhammadfahimma
Explorer

After a recent upgrade to Splunk ES 8.0.2, we have observed that none of the drill downs for detection based searches are available in the mission control screen anymore. Don't see any errors that might hint any abnormality. Has anyone come across a similar issue? How can this issue be debugged?

Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @muhammadfahimma 

I believe you may be experiencing a bug (BLUERIDGE-13575) which is a known issue with ES 8.0.2 (See https://docs.splunk.com/Documentation/ES/8.0.2/RN/KnownIssues)

If this is the issue then you may find the following workaround solves the issue until fixed in the product:

Workaround:
Remove `source` before sending to detection.
add `| fields - source` to end of search

Either way, I would suggest raising a support case, as even if it is this particular bug they will be able to associate it to your account and keep you updated with progress and resolution.

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

muhammadfahimma
Explorer

I don't think that is the case, the drilldowns are not appearing at all

0 Karma

livehybrid
SplunkTrust
SplunkTrust

In that case @muhammadfahimma  I think it is best to get this raised with Splunk Support, they should let you know the reference number once it has been logged and you can track it on the Release Notes (https://docs.splunk.com/Documentation/ES/latest/RN/NewFeatures) page.

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

0 Karma

muhammadfahimma
Explorer

thank you @livehybrid  i ended up creating a ticket with splunk support

kiran_panchavat
SplunkTrust
SplunkTrust

@muhammadfahimma 

Please review the following, and I kindly request you to raise a Splunk support ticket.

Investigate findings using drilldown searches and dashboards in Splunk Enterprise Security - Splunk ...

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

muhammadfahimma
Explorer

I'm following the same steps, but don't see the drill down appearing

0 Karma

SudhaP54
Engager

Hi @muhammadfahimma

Did you get any updates from the Splunk team?

I have installed ES 8.2.0 on the on prem Splunk instance, created an EBD and added the drill-down searches in the Detection Editor, but these are missing in the Mission Control detection page.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...