Skip to content
Notifications
Clear all

Anyone else's ES Notables taking 5+ minutes to populate after detection?

1 Posts
1 Users
0 Reactions
2 Views
(@juliep)
Trusted Member
Joined: 1 week ago
Posts: 51
Topic starter   [#5261]

I've been evaluating Splunk ES for a few weeks now, and I'm seeing a consistent delay in our test environment. After a correlation search fires and creates a notable event, it's taking over five minutes for that notable to actually appear in the Incident Review dashboard.

Our searches and detections seem to run on time. It's just this final step that's slow. Is this typical? I'm trying to understand if this is a configuration issue on our end or a known characteristic.

I'm cautious about scaling our use case if this is the normal latency. How are others handling real-time response if the notables aren't populated quickly?



   
Quote