Troubleshoot detections with multiple drill-down searches
Issue
An error might occur in the Analyst Queue page if two or more drill-down searches are saved using the same name such as "View all findings in Search".
Cause
In Splunk Enterprise Security, the default drill down search that is associated with a detection is identified by the same name as the detection on the finding-based detection editor. This can cause errors if two or more drill down searches are created and saved using the same name.
Solution
Do not create multiple drill-down searches with the same default name in the same detection. Instead, use token or prop values to identify drill down searches in a detection. You can also delete a drill-down search with the same name such as "View all findings in Search" if it is not the first drill-down search for the detection.
Troubleshoot detections with special characters | Troubleshoot risk modifiers in Splunk Enterprise Security |
This documentation applies to the following versions of Splunk® Enterprise Security: 8.1.0
Feedback submitted, thanks!