Super Administrators can see the various events associated to an EDR incident. The cloned Security Analyst role is unable to view any of the events on any incident.
Release : 14.3 RU6
The cloned security role didn't properly provide rights to the events, causing the event lists to show as empty. The cloned role was either corrupted or not cloned correctly.
Clone the Security Analyst security role again and assign any customized rights. Check to ensure this resolved the issue by checking a user in the role can see the events.