Splunk Enterprise Security
Highlighted

Splunk Enterprise security Incident Review table not showing.

Builder

Hi All,
Would like to know what causes this issue , please see screenshot attached.
There's an event "42" showing and time range is showing , but the table is not showing.
SplunkEnterpriseSecuritySuite = version :5.3.0

alt text

Highlighted

Re: Splunk Enterprise security Incident Review table not showing.

SplunkTrust
SplunkTrust

Hi @jadengoho,

Did you try clearing your browser cache or connect using another browser ? Seems like broken or cached CSS

Cheers,
David

Highlighted

Re: Splunk Enterprise security Incident Review table not showing.

Builder

Hi @DavidHourani - i tried restarting my laptop and reconnecting to the internet.Will try clearing browser cache when it happend again.

0 Karma
Highlighted

Re: Splunk Enterprise security Incident Review table not showing.

SplunkTrust
SplunkTrust

@jadengoho, that's great to hear ! Please accept the answer if your problem is solved 🙂

0 Karma
Highlighted

Re: Splunk Enterprise security Incident Review table not showing.

Builder

@DavidHourani - i tried clearing cache, changing browser and restarting my device but still issue occur.

0 Karma
Highlighted

Re: Splunk Enterprise security Incident Review table not showing.

SplunkTrust
SplunkTrust

Ummm.. could you please check what you get if you run index=notable from the search interface ? That will help you make sure that those notables are actually populated and not empty events.
If index=notable is working then try this to ensure that events from incident review are there : |incident_review
Also play around with the time picker to see if you can see older events on both searches and on the incident review page.

Highlighted

Re: Splunk Enterprise security Incident Review table not showing.

SplunkTrust
SplunkTrust

There are 42 matching events ... I reckon this ES has found the answer to everything 😉

cheers, MuS

Highlighted

Re: Splunk Enterprise security Incident Review table not showing.

SplunkTrust
SplunkTrust

I guess we're going to have to wait another 7½ million years for the results to display ...

Highlighted

Re: Splunk Enterprise security Incident Review table not showing.

Builder

@MuS - what could be the reason behind this ?

0 Karma
Highlighted

Re: Splunk Enterprise security Incident Review table not showing.

Builder

@DavidHourani - search is returning results, and when i change the time picker = time range shows the event count per day - but the table is not showing anything.
Also the pagination is showing. tried to change page still not showing.

0 Karma