Splunk Enterprise Security

Why is Splunk ES missing notable events?

iamtheclient20
Explorer

Hi Good morning.

We have a SH cluster and Indexer cluster. we have received a complain from SOC analyst some of notable events already exists(example last month or a week ago) are missing now or no longer visible on incedent review tab. But, when we try to run again the SPL on that day we got the result.

When we try to search the `notable` | search event_id = "the event id of notable" no result found.

NOTE:
-The storage is big.
-Some complain notable events present last week or last month are no longer visible now or they cannot search, but when we try to run the SPL on that day we got the result.

Can someone guide me, what are the things need to check to pinpoint the cause of this concern we have now. I am new in splunk.




Labels (1)
Tags (2)
0 Karma

Swarm_Security
New Member

I would check my indexes, as well as my hot and cold storage settings. Maybe they're being offloaded, since thresholds are being met (and backed up hopefully). 

0 Karma

lakscust01
Explorer

@iamtheclient20  Is the SOC using Incident review screen?  Are you able to use event_id="your value" and adjust the timerange and are you able to see it?

0 Karma

iamtheclient20
Explorer

Yes, we are able to use the event_id="value". But, no result found.

Thanks.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...