Splunk Enterprise Security

No Notables is getting generated however i can get the results when correlation searches are run mannually

saurabhsumangat
New Member

Since morning i am observing my notables are not getting created.
I can see the Notable names in Security posture but once i click on that it doesnt show any results.

when i copy paste the same search on searching and run manually it gives proper results.

What all are the checklist i need to check for this issue?

0 Karma

DavidHourani
Super Champion

Hi @saurabhsumangate,

Is this happening to all your notables ? Or only new ones that you have created ? Also did you check over which time you're running the search ? It could be that you're just on the wrong timeframe.

0 Karma

saurabhsumangat
New Member

Hey David,

This is happening to all the notables which used to generate earlier

0 Karma

DavidHourani
Super Champion

Could be a cookie issue, could you try clearing your browser's cache ?

0 Karma

saurabhsumangat
New Member

This has been resolved automatically.
Do you have any idea, what could be the reason for this behavior?

0 Karma

DavidHourani
Super Champion

it's most probably a browser incompatibility issue.. I've seen it happen with IE and Edge. When results don't show but you know they are there first step should be clearing the cache and logging back in 🙂

0 Karma

saurabhsumangat
New Member

sure.. i ll try it again later

0 Karma

saurabhsumangat
New Member

but my Notable graph in incident review has shown no spikes during a certain interval of time.. is it still related to browser compatibility?

0 Karma

DavidHourani
Super Champion

check the search building the graph, if when you run the search you have nothing at all then that means your correlation searches had stopped, if you do get results it's just a display issue

0 Karma
Get Updates on the Splunk Community!

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...