Hello,
I am new to Splunk ES , I have just enabled all the Correlation search, but I do not get any notables in the incident review section.
Do I need to add some more configurations.
Thank you for your time.
Just because you enabled a Correlation Search doesn't mean that you have proper data (properly parsed, possibly CIM-compliant, possibly in an accelerated data model).
Just because you enabled a Correlation Search doesn't mean that you have proper data (properly parsed, possibly CIM-compliant, possibly in an accelerated data model).