Splunk Enterprise Security

Splunk Incident Review Adaptive Response not Working

burakatabay
Path Finder

Hi splunkers,
When ı research an incident and press the ESCU-Contextualize
and ESCU-Contextualize return a empty page status=failure
Why I see failure error ?

alt text

Labels (1)

andsov
Explorer

Did you ever solve this problem?

0 Karma

alonsocaio
Contributor

It looks like the search didn't find the expected data in that context. Have you checked the recommended steps? Does your Splunk data matches them?

0 Karma

burakatabay
Path Finder

Yes matches them.

0 Karma

alonsocaio
Contributor

Also, check user permissions to the resources listed in recommended steps. And if you are able, try running this adhoc search with admin user.

0 Karma

burakatabay
Path Finder

I try admin user
Result is same

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...