Splunk Enterprise Security

Enterprise Security App

careoregon
Engager

Error in 'SearchOperator:loadjob': Cannot find artifacts for savedsearch_ident 'admin:SplunkEnterpriseSecuritySuite:ESS - Notable Events'

I get the above error in all the panels of the Security Posture in the Enterprise Security App.

0 Karma

aelliott
Motivator
0 Karma

aelliott
Motivator

on that post at the end, @MasterOogway posted:
"Usually this shows up when your trying to compare results from a current search to a previous one and the results from the earlier search cannot be found. Appears to be harmless knowing this will go away once the search condition is met."

0 Karma

careoregon
Engager

I could be wrong but I don't think that it's a permissions issue. Even when I login as the default splunk admin I still get the error.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...