Splunk Enterprise Security

Splunk Enterprise Security: In the Incident Review page, what is the "Time" referring to?

splunkrocks2014
Communicator

Hi. Does anyone know what "Time" is referring to from "Incident Review" from Splunk Enterprise Security (see image below)? As seen from picture, there are more 1 incident triggered in "9/23/16 9:55:08.000 PM". Is this timestamp when the use case was triggered? Where is this timestamp stored from the backend objects such as kvstores?

Incident Review

0 Karma
1 Solution

jstoner_splunk
Splunk Employee
Splunk Employee

The Time in the dropdown is associated with _time as found in the notable index. Seeing that you have a number of events triggered at the exact same time, you likely have multiple matches and results returned for that correlation search. You might want to look at throttling or refining your search a bit unless you were expecting to get a bunch of notable events at the same time like this. Yes, the timestamp would be associated with the time that the correlation search was set to run, give or take a few seconds for it to complete.

View solution in original post

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@splunkrocks2014 - Did the answer provided by jstoner help provide a solution to your question? If yes, please don't forget to resolve this post by clicking "Accept". If no, please leave a comment with more feedback. Thanks!

0 Karma

jstoner_splunk
Splunk Employee
Splunk Employee

The Time in the dropdown is associated with _time as found in the notable index. Seeing that you have a number of events triggered at the exact same time, you likely have multiple matches and results returned for that correlation search. You might want to look at throttling or refining your search a bit unless you were expecting to get a bunch of notable events at the same time like this. Yes, the timestamp would be associated with the time that the correlation search was set to run, give or take a few seconds for it to complete.

0 Karma
Get Updates on the Splunk Community!

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

What's New in Splunk Observability Cloud and Splunk AppDynamics - May 2025

This month, we’re delivering several new innovations in Splunk Observability Cloud and Splunk AppDynamics ...