Splunk Enterprise Security

Splunk Enterprise Security: In the Incident Review page, what is the "Time" referring to?

splunkrocks2014
Communicator

Hi. Does anyone know what "Time" is referring to from "Incident Review" from Splunk Enterprise Security (see image below)? As seen from picture, there are more 1 incident triggered in "9/23/16 9:55:08.000 PM". Is this timestamp when the use case was triggered? Where is this timestamp stored from the backend objects such as kvstores?

Incident Review

0 Karma
1 Solution

jstoner_splunk
Splunk Employee
Splunk Employee

The Time in the dropdown is associated with _time as found in the notable index. Seeing that you have a number of events triggered at the exact same time, you likely have multiple matches and results returned for that correlation search. You might want to look at throttling or refining your search a bit unless you were expecting to get a bunch of notable events at the same time like this. Yes, the timestamp would be associated with the time that the correlation search was set to run, give or take a few seconds for it to complete.

View solution in original post

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@splunkrocks2014 - Did the answer provided by jstoner help provide a solution to your question? If yes, please don't forget to resolve this post by clicking "Accept". If no, please leave a comment with more feedback. Thanks!

0 Karma

jstoner_splunk
Splunk Employee
Splunk Employee

The Time in the dropdown is associated with _time as found in the notable index. Seeing that you have a number of events triggered at the exact same time, you likely have multiple matches and results returned for that correlation search. You might want to look at throttling or refining your search a bit unless you were expecting to get a bunch of notable events at the same time like this. Yes, the timestamp would be associated with the time that the correlation search was set to run, give or take a few seconds for it to complete.

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...