Troubleshoot search results
You might get unexpected search results if you inadvertently use index time as the Time Tange in your correlation search.
Cause | Solution |
---|---|
Unexpected search results from the correlation search | Follow these steps to check whether the search is using index time:
|
Troubleshoot missing notable events in Splunk Enterprise Security | Turn on debug logging in Splunk Enterprise Security |
This documentation applies to the following versions of Splunk® Enterprise Security: 7.3.0, 7.3.1, 7.3.2, 7.3.3
Feedback submitted, thanks!