Any time I load the debug/refresh endpoint, correlation searches stop running. Or, at least, they stop producing notable events. Is this expected behavior and if not, what's going on?
Splunk Enterprise 6.2.2, Splunk App for Enterprise Security 3.2.
I don't know what is going on, but I see the same behavior on 6.1.6 and 3.1.1.
Restarting Splunk on the ESS box fixes the glitch for me.