Splunk Enterprise Security

Splunk Enterprise Security: How to troubleshoot why Incident Review hangs on "loading"?

arunkuriakose
Explorer

Hi Team

My Splunk Enterprise Security Incident Review is not loading...It just shows "loading" for a long time. I created a notable event and also tried copying the same code to create a separate incident review button, but no luck...please help

Thanks in advance

0 Karma

arandriamanohis
Engager

Not sure if this has been resolved, but I encountered the same issue. It turns out it's the contents of the data folder in SA-ThreatIntelligence/local , likely from customizations that we've done. The incident_review.xml file in data/ui/views is completely different between the version I was coming from (4.1.x) and the one I'm upgrading to (4.7.x)

TL;DR check SA-ThreatIntelligence/local/data/ and move it somewhere, restart Splunk and check if it works. If it does, you'll have to restore the customizations you made in the first place.

LukeMurphey
Champion

Can you try looking into your browser console for errors?

0 Karma

arunkuriakose
Explorer

Can you guide me on checking that?

0 Karma

niemesrw
Path Finder

Hi arunkuriakose - I'd recommend you use chrome and start the 'developer tools' to see if there are any errors. Incident review is most likely some javascript and perhaps your browser is blocking the code for some reason.

You might also try clearing everything in your browser and trying a different browser to see if the same thing applies to different situations - I've seen weirdness before with chrome and safari exhibiting different behavior. Also try incognito mode and see if that does something different.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...