Splunk Enterprise Security

Why is my Correlation search not showing up in Incident Review bench ?

neerajs_81
Builder

Hello All,
I have created couple of correlation searches , ensured to select "Notable" under the Adaptive Responsive section  of these searches so that they create a notable but yet these are not visible in the Drop Down list of  Incident Review dashboard.   When i run the searches manually they haven't yet produced any events or results because a matching event hasn't yet occured but shouldn't their names be at least be visible in Incident Review if they are enabled?  Do i need to wait for the searches to produce an event and only then will they populate in IR ?      I have made sure to check the lookup file which these searches are using, is set to Global permissions.

neerajs_81_0-1635342239442.png

 

 

ro_mc
Path Finder

It sounds like you're following the correct process, so the best way to test this is to simply generate notable events to confirm your theory. Simple search of "index=_internal | head 1" should suffice. Verify that the notable exists in index=notable and then proceed to the incident review dashboard.

If Splunk is otherwise working fine, but you continue to see no new incident review data. review the post installation steps for Splunk Enterprise Security. Try clearing the cache and restarting the browser if required, and restart Splunk if this has not already been performed during the installation process.

If problems persist, check the splunkd.log for errors (index_internal source=*splunkd.log sourcetype=splunkd), as well as related components like the mongod service for the KVstore. Details on MongoDB and KVstore troubleshooting can be found at the link below.

https://docs.splunk.com/Documentation/Splunk/8.2.2/Admin/TroubleshootKVstore

If Splunk ES is not performing as intended, there will be logs, and Splunk will provide them.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...