Hi Splunkers,
we are not able to see any notable events from yesterday in ES app even though we have not made changes to the configurations.
I have checked the scheduler.log file and there is no information about the running of correlation rules from yesterday where as i can see next schedule run time in splunk console. And also i have checked the splunkd.log i couldn't find any trace.
Does anyone of you have faced the same situation? Can you please someone help us on this how to process further .
Thanks
Pench
So are you still not seeing any notables or did this just happen over yesterday?
Nonetheless, you should open a splunk support case for this, because troubleshooting it over a forum won't very efficient. And if ES just stopped working, that sounds like something support should hear about.
Other than that, maybe start looking for errors/issues sometime around the last notable you saw. And of course if this is still an issue, try restarting splunk (but I'm sure you've tried that)