Splunk Enterprise Security

SplunkEnterpriseSecuritySuite: Why is correlation search next scheduled time in the past?

tokio13
Path Finder

Hello,

What could be the explanation for a Correlation Search that is set to run live, on the Next Scheduled Time tab in /app/SplunkEnterpriseSecuritySuite/ess_content_management it appears that the Next Scheduled Time to be in the past. (today is 3rd of march) This is also not triggering any events in the Incident Review Tab in Enterprise Security app.

tokio13_0-1646313140697.png

 

Thanks to anyone that can give any hints

I appreciate

 

0 Karma

starcher
Influencer

check the search. It’s it set to continuous mode in the correlation search settings? If yes. Then look in job activity at a recent run. Most likely your search takes longer to complete than the scheduled interval. This causes the backsliding in time. Rewrite the search to be more efficient and complete within the desired window. 

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...