PowerConnect for SAP Solutions
Breadcrumbs

KB 174 - Orphaned Correlation Searches in ES Content Pack Not Generating Notable Events

Category: Problem

Priority: Critical

Platform: Splunk

Version: 1 from 23.03.2023

Description

After installing the PowerConnect SAP Content Pack for Enterprise Security, you may notice that Notable Events are not being generated for your Enterprise Security instance. When you go to Content Management and filter on the content pack searches, you see that there are no “Next Scheduled Times,“ despite the searches being enabled.

You may also see a Message notification indicating a number of “orphaned searches.”

image-20230324-195748.png

Cause

“Orphaned” searches have no established owner in the Splunk environment, and therefore cannot be run unless they are assigned a user.

Resolution

  • While logged in with an administrative user account in your Splunk instance, go to “Settings” and “All configurations”

  • image-20230324-195909.png

    At the top of the “All configurations” page, click “Reassign knowledge objects.”

  • image-20230324-200042.png

    On the following page, make use of the filters to narrow the view down to the orphaned searches in the PowerConnect SAP Content Pack for Enterprise Security. Here are the recommended filter settings:

    • The “Orphaned” toggle filter

    • The “App” filter set to “PowerConnect SAP Content Pack for Enterprise Security

  • image-20230324-200334.png

    Select all of the searches and click “Edit Selected Knowledge Objects,” then “Reassign”

  • image-20230324-201706.png

    For “New Owner,” assigning “Nobody” is recommended, but an account with the requisite search provisioning (dependent on your data volume) is also acceptable.

  • image-20230324-200652.png

    Now that the searches have been reassigned, they should begin scheduling automatically. Click “Done” when the reassignment finishes.

  • image-20230324-203057.png