Splunk Enterprise Security

SplunkEnterpriseSecuritySuite: Why is correlation search next scheduled time in the past?

tokio13
Path Finder

Hello,

What could be the explanation for a Correlation Search that is set to run live, on the Next Scheduled Time tab in /app/SplunkEnterpriseSecuritySuite/ess_content_management it appears that the Next Scheduled Time to be in the past. (today is 3rd of march) This is also not triggering any events in the Incident Review Tab in Enterprise Security app.

tokio13_0-1646313140697.png

 

Thanks to anyone that can give any hints

I appreciate

 

0 Karma

starcher
SplunkTrust
SplunkTrust

check the search. It’s it set to continuous mode in the correlation search settings? If yes. Then look in job activity at a recent run. Most likely your search takes longer to complete than the scheduled interval. This causes the backsliding in time. Rewrite the search to be more efficient and complete within the desired window. 

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...