Notifications
Clear all
Topic starter
16/07/2026 7:47 am
I've been evaluating Splunk ES for a few weeks now, and I'm seeing a consistent delay in our test environment. After a correlation search fires and creates a notable event, it's taking over five minutes for that notable to actually appear in the Incident Review dashboard.
Our searches and detections seem to run on time. It's just this final step that's slow. Is this typical? I'm trying to understand if this is a configuration issue on our end or a known characteristic.
I'm cautious about scaling our use case if this is the normal latency. How are others handling real-time response if the notables aren't populated quickly?