Splunk Enterprise Security

Splunk Enterprise Security: How to troubleshoot why Incident Review hangs on "loading"?

New Member

Hi Team

My Splunk Enterprise Security Incident Review is not loading...It just shows "loading" for a long time. I created a notable event and also tried copying the same code to create a separate incident review button, but no luck...please help

Thanks in advance

0 Karma

Not sure if this has been resolved, but I encountered the same issue. It turns out it's the contents of the data folder in SA-ThreatIntelligence/local , likely from customizations that we've done. The incident_review.xml file in data/ui/views is completely different between the version I was coming from (4.1.x) and the one I'm upgrading to (4.7.x)

TL;DR check SA-ThreatIntelligence/local/data/ and move it somewhere, restart Splunk and check if it works. If it does, you'll have to restore the customizations you made in the first place.


Can you try looking into your browser console for errors?

0 Karma

New Member

Can you guide me on checking that?

0 Karma

Path Finder

Hi arunkuriakose - I'd recommend you use chrome and start the 'developer tools' to see if there are any errors. Incident review is most likely some javascript and perhaps your browser is blocking the code for some reason.

You might also try clearing everything in your browser and trying a different browser to see if the same thing applies to different situations - I've seen weirdness before with chrome and safari exhibiting different behavior. Also try incognito mode and see if that does something different.

0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!