Splunk Enterprise Security

Why can't I see any items in Adaptive Response Actions and error "Notable Info could not be obtained: : undefined"?

jhy
Observer

Hi Splunker,

When creating or editing a new Correlation Search, the items of "Adaptive Response Actions" do not appear and the following error occurs.
The peculiarity only occurs when connecting from a macbook, and works normally when connecting from Windows.

jhy_0-1686699998634.png

The current environment is Splunk 9.0.5 + ES 7.1.1, but this has occurred since ES 7.x, a year ago.

 

Thanks

0 Karma

meetmshah
Contributor

This has been answered in https://community.splunk.com/t5/Splunk-Enterprise-Security/Notable-info-could-not-be-obtained-uniden...

 

The issue was related to KV store, while troubleshooting we found that the KV store status of starting hence we checked whether the cluster members are able to communicate to each other on KV port. Enabling the KV store port between all the cluster member resolved the issue.
0 Karma

jhy
Observer

Thanks for your answer.

I also saw the link you sent before, but in my case it is not a search head cluster environment.
My problem is that when I connect from the windows client, it works normally, but when I connect from the macbook, a problem occurs.
Of course kvstore is working normally.

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...