Splunk Enterprise Security

Why is my Correlation search not showing up in Incident Review bench ?

neerajs_81
Builder

Hello All,
I have created couple of correlation searches , ensured to select "Notable" under the Adaptive Responsive section  of these searches so that they create a notable but yet these are not visible in the Drop Down list of  Incident Review dashboard.   When i run the searches manually they haven't yet produced any events or results because a matching event hasn't yet occured but shouldn't their names be at least be visible in Incident Review if they are enabled?  Do i need to wait for the searches to produce an event and only then will they populate in IR ?      I have made sure to check the lookup file which these searches are using, is set to Global permissions.

neerajs_81_0-1635342239442.png

 

 

ro_mc
Path Finder

It sounds like you're following the correct process, so the best way to test this is to simply generate notable events to confirm your theory. Simple search of "index=_internal | head 1" should suffice. Verify that the notable exists in index=notable and then proceed to the incident review dashboard.

If Splunk is otherwise working fine, but you continue to see no new incident review data. review the post installation steps for Splunk Enterprise Security. Try clearing the cache and restarting the browser if required, and restart Splunk if this has not already been performed during the installation process.

If problems persist, check the splunkd.log for errors (index_internal source=*splunkd.log sourcetype=splunkd), as well as related components like the mongod service for the KVstore. Details on MongoDB and KVstore troubleshooting can be found at the link below.

https://docs.splunk.com/Documentation/Splunk/8.2.2/Admin/TroubleshootKVstore

If Splunk ES is not performing as intended, there will be logs, and Splunk will provide them.

0 Karma
Get Updates on the Splunk Community!

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...