Splunk Search

Notable event index is empty.

gl_splunkuser
Path Finder

Hello everyone.

I am trying to deploy ESS, but I having some trouble with the notable events.

I can not see results at the Incident Review dashboard and this is because the notable event index is empty

gl_splunkuser_0-1618001686453.png

I created a correlation search  and as part of the adaptative response action a notable event had to be create.

But is not working, so I decided to run the search from de alert and there I can see results. 

Also I followed the next guide  https://docs.splunk.com/Documentation/ES/6.5.0/Admin/Troubleshootnotables 

And I found this :

gl_splunkuser_1-1618002078274.png gl_splunkuser_2-1618002108062.png

gl_splunkuser_3-1618002139521.png

As you can see everything looks ok. 

It is important to mention that some searches have been skipped, but not all of them and also I didn't change anything at the Splunk_SA_CIM, read that sometimes that can be a problem, but isn't my case.

Here a let a image of the result of this search index=_internal sourcetype=scheduler

gl_splunkuser_0-1618002915053.png

 

I really don't know what is happening.

 

I will really appreciate the help.

Regards

 

 

Labels (1)
0 Karma
1 Solution

scelikok
SplunkTrust
SplunkTrust

Hi @gl_splunkuser,

Is your Splunk standalone or distributed? If your Splunk instance is not standalone, you have to create notable index on your indexers. 

If this reply helps you an upvote and "Accept as Solution" is appreciated.

View solution in original post

gl_splunkuser
Path Finder

That have a lot of sense.

Thank you so much.

 

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @gl_splunkuser,

Is your Splunk standalone or distributed? If your Splunk instance is not standalone, you have to create notable index on your indexers. 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...