Troubleshoot Activity logs in Splunk Enterprise Security

Activity logs provide a tamper-proof audit trail for changes made to a finding, finding group, or investigation. Following are some of the common issues with troubleshooting tips:

Activity log is empty

Issue: Activity log is empty and the Load Activity log button does not resolve.

Cause: Search is still running due to a large history and a slow index.

Resolution:
  • Check that the search handler received the request and created a job.
  • Verify that the mc_history index has events for the object.
  • Check the Splunk search query for errors.

Permission issues

Issue: Permission to access and get history from the Activity logs is denied.

Cause:
  • You don't have the mc_investigation_read capability.
  • You don't have the read capability for the queue to which the investigation belongs.

Resolution: Contact your Splunk administrator to request full access permissions.

Inaccurate results in the Activity log

Issue: Results are truncated and the Activity log is missing old events

Cause: The maximum events that the Activity log can hold is 10,000 events.

Resolution: For objects with long histories, narrow the time range or use report = true on the REST endpoint.

History of the record is missing​

Issue:Included findings history is missing.

Cause:Can be an access issue or macro construction issue or UI issue.

Resolution:
  • Ensure that the View change history button was selected from the UI for All and not Investigation only or Finding group only.​
  • You must have access to the queue for the child findings.​
  • Macro must contain the true parameter.