We are unable to see our notable events when correlation search criteria met. Upon investigation, found out that notable index is empty, which resulting es_notable_events kvstore lookup empty. Correlation search has no issue because we could see other AR actions triggered except notable. Our environment: 2 indexers with cluster configuration, 1 SH, 1 stack of MC/License master/Deployment server, 1 Cluster Master. ES version: 6.2.0, Enterprise version: 8.0.5 Hope someone can give me a hand 🙂
... View more