Splunk Enterprise Security

SplunkEnterpriseSecuritySuite: Why is correlation search next scheduled time in the past?

tokio13
Path Finder

Hello,

What could be the explanation for a Correlation Search that is set to run live, on the Next Scheduled Time tab in /app/SplunkEnterpriseSecuritySuite/ess_content_management it appears that the Next Scheduled Time to be in the past. (today is 3rd of march) This is also not triggering any events in the Incident Review Tab in Enterprise Security app.

tokio13_0-1646313140697.png

 

Thanks to anyone that can give any hints

I appreciate

 

0 Karma

starcher
SplunkTrust
SplunkTrust

check the search. It’s it set to continuous mode in the correlation search settings? If yes. Then look in job activity at a recent run. Most likely your search takes longer to complete than the scheduled interval. This causes the backsliding in time. Rewrite the search to be more efficient and complete within the desired window. 

0 Karma
Get Updates on the Splunk Community!

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...