Incident review is not working after Splunk ESS 4.1.1 and CIM Upgrade.
Also checked for data sources and their respective correlation searches enabled, but still i cant see any notable events or data in incident review?
@splunkrajkrk - Did the answer provided by ekost help provide a working solution to your question? If yes, please don't forget to resolve this post by clicking "Accept". If no, please leave a comment with more feedback. Thanks!
es_notable_events
to show data in the index. Available fields are listed on the dev site here.|inputlookup incident_review_lookup
. There’s also REST commands for KVStore are on the dev site here. If none of these results in a clue towards what is wrong, consider filing a support case.
Do we have answer to this question yet? I have also upgraded the splunk ES to latest version and Incident Review page is not loading.