Splunk Enterprise Security

Threat Activity Detected Notable not triggered

b_chris21
Communicator

Hello everyone,

I have added an IP on local_intel_ip.csv and it now appears on Threat Artifact panel. The correlation search "Threat Activity Detected" is enabled with Adaptive Response Actions a Notable and Risk Analysis.

A notable event was triggered with this IP as destination IP, but the aforementioned Notable (Threat Activity Detected) was never triggered. 

Any idea on what I might have done wrong?

Thank you in advance.

Chris

Labels (2)
Tags (1)
0 Karma
1 Solution

b_chris21
Communicator

After troubleshooting I found the solution: 

I had the Acceleration of Alerts datamodel disabled. Once enabled, the alerts started popping up to my Incident Review console.

View solution in original post

0 Karma

b_chris21
Communicator

After troubleshooting I found the solution: 

I had the Acceleration of Alerts datamodel disabled. Once enabled, the alerts started popping up to my Incident Review console.

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...