Splunk Enterprise Security

Splunk Incident Review Adaptive Response not Working

burakatabay
Path Finder

Hi splunkers,
When ı research an incident and press the ESCU-Contextualize
and ESCU-Contextualize return a empty page status=failure
Why I see failure error ?

alt text

Labels (1)

andsov
Explorer

Did you ever solve this problem?

0 Karma

alonsocaio
Contributor

It looks like the search didn't find the expected data in that context. Have you checked the recommended steps? Does your Splunk data matches them?

0 Karma

burakatabay
Path Finder

Yes matches them.

0 Karma

alonsocaio
Contributor

Also, check user permissions to the resources listed in recommended steps. And if you are able, try running this adhoc search with admin user.

0 Karma

burakatabay
Path Finder

I try admin user
Result is same

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...