After upgrading to 3.0.4 on Splunk 8.0.2006, the incident table in Incident Posture isn't loading - 0 results.
It seems if there is nothing specified in Filter input, the macro all_alerts() fails to run correctly
If I enter a filter, eg app=*, the macro runs mine
I've worked around by making app=* the default filter.
After upgrading to 3.0.4 on Splunk 8.0.2006, the incident table in Incident Posture isn't loading - 0 results.
It seems if there is nothing specified in Filter input, the macro all_alerts() fails to run correctly If I enter a filter, eg app=*, the macro runs mine
I've worked around by making app=* the default filter.