After a recent upgrade to Splunk ES 8.0.2, we have observed that none of the drill downs for detection based searches are available in the mission control screen anymore. Don't see any errors that might hint any abnormality. Has anyone come across a similar issue? How can this issue be debugged?
I believe you may be experiencing a bug (BLUERIDGE-13575) which is a known issue with ES 8.0.2 (See https://docs.splunk.com/Documentation/ES/8.0.2/RN/KnownIssues)
If this is the issue then you may find the following workaround solves the issue until fixed in the product:
Workaround:
Remove `source` before sending to detection.
add `| fields - source` to end of searchEither way, I would suggest raising a support case, as even if it is this particular bug they will be able to associate it to your account and keep you updated with progress and resolution.
Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards
Will
I don't think that is the case, the drilldowns are not appearing at all
In that case @muhammadfahimma I think it is best to get this raised with Splunk Support, they should let you know the reference number once it has been logged and you can track it on the Release Notes (https://docs.splunk.com/Documentation/ES/latest/RN/NewFeatures) page.
Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards
Will
thank you @livehybrid i ended up creating a ticket with splunk support
Please review the following, and I kindly request you to raise a Splunk support ticket.
I'm following the same steps, but don't see the drill down appearing
Did you get any updates from the Splunk team?
I have installed ES 8.2.0 on the on prem Splunk instance, created an EBD and added the drill-down searches in the Detection Editor, but these are missing in the Mission Control detection page.