Splunk Enterprise Security

Splunk Notable Events not showing default owner

Prachi_Kothari
Engager

Hello, 

Hope you are  doing well!

I have updated exiting correlation alert in Splunk as  notable event which previously used to send email notification to 'x'. I have selected 'Default Owner' as 'leave as system default' (i.e. unassigned) but still when it trigger alerts in Splunk - Incident Review page, it showing owner as 'x'  (same as email owner) not as default owner i.e. unassigned.

Prachi_Kothari_0-1637160157804.png

Can someone help me with this?

 

Thanks in advance!

Labels (2)
0 Karma

Prachi_Kothari
Engager

Temporally, fixed this issue by hardcoding the parameters as per the screenshot but still the actual reason why it wasn't showing default parameters is unknown.  

Prachi_Kothari_0-1637642072559.png

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...