Splunk Enterprise Security

Will Splunk notables reflect with delay in timestamp on incident dashboard when they moved from "Dev" to "Prod"stage?

NikhilTeja22
New Member

Hi,

Good day to you!

I quickly wanted to understand whether the Splunk notables will reflect with delay in timestamp on incident dashboard when they moved from "Dev" to "Prod" stage?

I often see bulk notables triggering with lag in time (assume today is 18th, alerts reflect with 17th or before dates) whenever SOC team pushes new use-case to Production queue (status: new)

Happy to know some context/knowledge around this

Cheers,

Labels (1)
0 Karma

NikhilTeja22
New Member

Can someone have a look at this query and assist please

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...