Splunk Enterprise Security

SplunkEnterpriseSecuritySuite: Why is correlation search next scheduled time in the past?

tokio13
Path Finder

Hello,

What could be the explanation for a Correlation Search that is set to run live, on the Next Scheduled Time tab in /app/SplunkEnterpriseSecuritySuite/ess_content_management it appears that the Next Scheduled Time to be in the past. (today is 3rd of march) This is also not triggering any events in the Incident Review Tab in Enterprise Security app.

tokio13_0-1646313140697.png

 

Thanks to anyone that can give any hints

I appreciate

 

0 Karma

starcher
Influencer

check the search. It’s it set to continuous mode in the correlation search settings? If yes. Then look in job activity at a recent run. Most likely your search takes longer to complete than the scheduled interval. This causes the backsliding in time. Rewrite the search to be more efficient and complete within the desired window. 

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...