Incident review is not working after Splunk ESS 4.1.1 and CIM Upgrade.
Also checked for data sources and their respective correlation searches enabled, but still i cant see any notable events or data in incident review?
↧