Splunk Search

Notable event index is empty.

gl_splunkuser
Path Finder

Hello everyone.

I am trying to deploy ESS, but I having some trouble with the notable events.

I can not see results at the Incident Review dashboard and this is because the notable event index is empty

gl_splunkuser_0-1618001686453.pnggl_splunkuser_0-1618001686453.png

I created a correlation search  and as part of the adaptative response action a notable event had to be create.

But is not working, so I decided to run the search from de alert and there I can see results. 

Also I followed the next guide  https://docs.splunk.com/Documentation/ES/6.5.0/Admin/Troubleshootnotables 

And I found this :

gl_splunkuser_1-1618002078274.pnggl_splunkuser_1-1618002078274.png gl_splunkuser_2-1618002108062.pnggl_splunkuser_2-1618002108062.png

gl_splunkuser_3-1618002139521.pnggl_splunkuser_3-1618002139521.png

As you can see everything looks ok. 

It is important to mention that some searches have been skipped, but not all of them and also I didn't change anything at the Splunk_SA_CIM, read that sometimes that can be a problem, but isn't my case.

Here a let a image of the result of this search index=_internal sourcetype=scheduler

gl_splunkuser_0-1618002915053.pnggl_splunkuser_0-1618002915053.png

 

I really don't know what is happening.

 

I will really appreciate the help.

Regards

 

 

Labels (1)
0 Karma
1 Solution

scelikok
SplunkTrust
SplunkTrust

Hi @gl_splunkuser,

Is your Splunk standalone or distributed? If your Splunk instance is not standalone, you have to create notable index on your indexers. 

If this reply helps you an upvote and "Accept as Solution" is appreciated.

View solution in original post

gl_splunkuser
Path Finder

That have a lot of sense.

Thank you so much.

 

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @gl_splunkuser,

Is your Splunk standalone or distributed? If your Splunk instance is not standalone, you have to create notable index on your indexers. 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...