We were using the real-time feature until we upgrade to 6.6.2. Apparently after version 6.6.0, real-time searches are no longer supported. I've asked the question again and had a co-worker reach out to our contact @ Splunk to see if we are missing something. In the mean time, I've created a dashboard using the `notable` macro and tailoring it to our needs. The panel that is looking for new events updates every 2 minutes, and has a drill down built in that allows the analyst to click the event which re-directs them to a preconfigured incident review page. From there they can work the events. I hope there is another solution, but this way works for now.
... View more