Splunk Enterprise Security

SplunkEnterpriseSecuritySuite: Why is correlation search next scheduled time in the past?

tokio13
Path Finder

Hello,

What could be the explanation for a Correlation Search that is set to run live, on the Next Scheduled Time tab in /app/SplunkEnterpriseSecuritySuite/ess_content_management it appears that the Next Scheduled Time to be in the past. (today is 3rd of march) This is also not triggering any events in the Incident Review Tab in Enterprise Security app.

tokio13_0-1646313140697.png

 

Thanks to anyone that can give any hints

I appreciate

 

0 Karma

starcher
SplunkTrust
SplunkTrust

check the search. It’s it set to continuous mode in the correlation search settings? If yes. Then look in job activity at a recent run. Most likely your search takes longer to complete than the scheduled interval. This causes the backsliding in time. Rewrite the search to be more efficient and complete within the desired window. 

0 Karma
Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...