Splunk Enterprise Security

Notable events stopped updating in Incidnet Review in ES app

kiranp2
New Member

Hi Splunkers,

we are not able to see any notable events from yesterday in ES app even though we have not made changes to the configurations.

I have checked the scheduler.log file and there is no information about the running of correlation rules from yesterday where as i can see next schedule run time in splunk console. And also i have checked the splunkd.log i couldn't find any trace.

Does anyone of you have faced the same situation? Can you please someone help us on this how to process further .

Thanks
Pench

0 Karma

maciep
Champion

So are you still not seeing any notables or did this just happen over yesterday?

Nonetheless, you should open a splunk support case for this, because troubleshooting it over a forum won't very efficient. And if ES just stopped working, that sounds like something support should hear about.

Other than that, maybe start looking for errors/issues sometime around the last notable you saw. And of course if this is still an issue, try restarting splunk (but I'm sure you've tried that)

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...