Splunk Enterprise Security

Splunk Enterprise Security: Why are notable events not created and notable alert_action is not triggered?

kwchang_splunk
Splunk Employee
Splunk Employee

One of my Splunk Enterprise Security customer's complained that sometimes the notable events are not created even when the corresponding raw data is there.
So I checked the scheduler log and found that there were cases that the "notable" alert_action was not triggered when the result_count was not "0".

Please see the red box in the screen capture below. This correlation search runs every 2 minutes. At 13:00:54, result_count was "1", but "notable" alert_action was not triggered.

alt text

This problem (missing notable events) happens randomly across almost all correlation searches they have, several times in a day.
Unfortunately, I couldn't find any clue from the splunkd log so far. There were no error or warning messages when these problems happened.

My customer is running ES 4.1.1 on Splunk 6.4.3. (search head clustering + multisite indexer clustering environment)

Any suggestion for troubleshooting would be very appreciated.
Thank you in advance.

0 Karma

smoir_splunk
Splunk Employee
Splunk Employee

Check the throttling of notable events for that search. If the search is throttling notable events, and the "randomly" skipped notable events fall into that time window, that would explain why a notable event isn't being created.

0 Karma

aglinowi
Engager

Did you find a resolution to this problem? I'm experiencing a very similar issue. Thanks

0 Karma

kwchang_splunk
Splunk Employee
Splunk Employee

Hi smoir. Thank you for your answer.
Already checked that. Throttling was not configured.

0 Karma

kwchang_splunk
Splunk Employee
Splunk Employee

Hi Smoir. I just found an ongoing support case which has very similar symptom with my case. I think, I need to contact support team. Thank you.

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...