Splunk Enterprise Security

Splunk ES APP Notables Events lookup clean

sumitkathpal
Explorer

Hi All,

Need help, We recently enable few alerts for testing which results into notable events . Now we have cleared the index=notable . All results got cleared but micro incident_review is updated and incident_reviewstill show the old notable events count.

Can any one help to flush this micro lookup incident_review?

Thanks in advance

0 Karma

sumitkathpal
Explorer

Any help?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...