Splunk Enterprise Security

Why am I unable to save correlation searches through Splunk Enterprise Security in the context of any custom app?

rwells2950
Engager

I cannot save correlation searches through Splunk Enterprise Security in the context of any custom app. After going to the Content Management page in ES, I cannot open my correlation searches (it just keeps loading). Can anyone help me with this please? Thank you ahead of time.

0 Karma

sduchene_splunk
Splunk Employee
Splunk Employee

FYI, in my case Chrome was behaving weirdly. using firefox solved the issue

0 Karma

aholzel
Communicator

Probably a bit late... but for anyone else having this problem. For me the solution was to change the app sharing permissions for the app the correlation search was saved in. When you set them to "global" everything works fine.

0 Karma

smoir_splunk
Splunk Employee
Splunk Employee

What version of Enterprise Security and what version of the Splunk platform are you using?

Is your custom app being imported into Enterprise Security, and are the knowledge objects exported into Enterprise Security?

Did you try clearing the browser cache of the page?

Are there any console errors when you try to load the page?

0 Karma

rwells2950
Engager

Splunk Version
6.5.1

SplunkEnterpriseSecuritySuite

4.5.1

Yes the app and knowledge objects are exported into ES

The browser cache of the page has been cleared and the issue still persists

And there are no errors firing, I am stuck at a loading page when trying to drill into the correlation searches pertaining to my custom app.

smoir_splunk
Splunk Employee
Splunk Employee

Thanks for the additional details, @rwells2950!

Have you previously been able to open these correlation searches on the Content Management page?

Do the titles of the searches contain special characters (such as umlauts on letters, en-dashes (–) or em-dashes (—))?

I'm guessing it might be a search name issue that allowed you to save the search, but not open it for editing, especially since the app is being imported without issue.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...