Skip to content

updating risk drilldowns#4016

Open
patel-bhavin wants to merge 8 commits intodevelopfrom
dd_risk
Open

updating risk drilldowns#4016
patel-bhavin wants to merge 8 commits intodevelopfrom
dd_risk

Conversation

@patel-bhavin
Copy link
Copy Markdown
Contributor

Fixes for issue : #3976

nasbench
nasbench previously approved these changes Apr 15, 2026
Copy link
Copy Markdown
Contributor

@nasbench nasbench left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Did not look at all for my sanity. But since this a search/replace it should all be good. I'll take care of the versions

@AndreiBanaru
Copy link
Copy Markdown
Contributor

This would show results but I think it doesn't render the intention:

  earliest_offset: 7d
  latest_offset: "0"

I've updated it for 1 detection in our dev environment and this is what I see in Splunk Web:
image

and when I click on the drilldown for a finding I have:
image

@patel-bhavin
Copy link
Copy Markdown
Contributor Author

patel-bhavin commented Apr 16, 2026

Hello @AndreiBanaru : i installed a build of the ESCU from this specific PR onto our test instance and it seems like this works as intended : You can note the time on the right side of the screenshot and i recommend to look under
"date & Time Range" to confirm if the time computation works as expected!

What splunk and ES version are you on ? I have tested this ES 8.4 and Splunk 10

I also noticed that ES adds the y and renders it in UI as 0y for latest_offset however this seems like a bug in ES and the functionality works as expected! Based on our testing : we will likely move forward with getting this PR shipped! Let us know if you have any concerns

image

Note:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants