Splunk Enterprise Security

Splunk Enterprise Security: Why can't I create an ad-hoc notable event after upgrade?

abalogh_splunk
Splunk Employee
Splunk Employee

We have just upgraded Splunk Enterprise 6.4.1 / Splunk Enterprise Security 4.1.1 to Splunk Enterprise 6.5.2 with Splunk Enterprise Security 4.5.2.

When I try to create an Ad-Hoc Notable Event I get the following error in the UI:

Failed to create notable event: Not Found

Firefox Debug:
https://splunk-es/en-US/splunkd/__raw/services/alerts/modaction_adhoc [HTTP/1.1 404 Not Found 16ms]

0 Karma
1 Solution

abalogh_splunk
Splunk Employee
Splunk Employee

Answering my own question for documentation purposes.

Make sure you have upgrade Splunk_SA_CIM as well since modaction_adhoc has been moved into Splunk_SA_CIM in later versions. Former installation was running CIM 4.3.1, upgraded to 4.6.0 and it solved the issue.

View solution in original post

0 Karma

abalogh_splunk
Splunk Employee
Splunk Employee

Answering my own question for documentation purposes.

Make sure you have upgrade Splunk_SA_CIM as well since modaction_adhoc has been moved into Splunk_SA_CIM in later versions. Former installation was running CIM 4.3.1, upgraded to 4.6.0 and it solved the issue.

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...