<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Enterprise Security: How to remove a notable event from the &amp;quot;Security Posture&amp;quot; dashboard after investigation? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-remove-a-notable-event-from/m-p/203219#M1089</link>
    <description>&lt;P&gt;This worked for me &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=notable search_name="*your notable title*" | delete 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 28 Nov 2019 05:00:11 GMT</pubDate>
    <dc:creator>apcsplunk</dc:creator>
    <dc:date>2019-11-28T05:00:11Z</dc:date>
    <item>
      <title>Splunk Enterprise Security: How to remove a notable event from the "Security Posture" dashboard after investigation?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-remove-a-notable-event-from/m-p/203213#M1083</link>
      <description>&lt;P&gt;I have a notable event seen in Splunk Enterprise Security's &lt;EM&gt;Security Posture&lt;/EM&gt; dashboard.&lt;BR /&gt;&lt;BR /&gt;
I have reviewed it and determined it to be a false positive.&lt;BR /&gt;
I want to remove it from view on the &lt;EM&gt;Security Posture&lt;/EM&gt; dashboard.&lt;/P&gt;

&lt;P&gt;Is there any way to do this?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2016 18:45:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-remove-a-notable-event-from/m-p/203213#M1083</guid>
      <dc:creator>mgrosholz</dc:creator>
      <dc:date>2016-06-10T18:45:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: How to remove a notable event from the "Security Posture" dashboard after investigation?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-remove-a-notable-event-from/m-p/203214#M1084</link>
      <description>&lt;P&gt;In the current form, there is no &lt;EM&gt;easy&lt;/EM&gt; way to delete a notable event. The basic idea here is that event your false positives, you want to categorize. So you could create a new class for false positives and classify these notables into this.&lt;/P&gt;

&lt;P&gt;See here : &lt;A href="http://docs.splunk.com/Documentation/ES/4.1.1/User/NotableEvents"&gt;http://docs.splunk.com/Documentation/ES/4.1.1/User/NotableEvents&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If you're really looking to delete the events, you'll need to look at the &lt;CODE&gt;incident_review&lt;/CODE&gt; and &lt;CODE&gt;notables&lt;/CODE&gt; macros, and where they are pulling the data from. In the latest versions of ES, notables are stored between KVStore, lookup files, and summary indexes..&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jun 2016 03:34:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-remove-a-notable-event-from/m-p/203214#M1084</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2016-06-11T03:34:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: How to remove a notable event from the "Security Posture" dashboard after investigation?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-remove-a-notable-event-from/m-p/203215#M1085</link>
      <description>&lt;P&gt;I don't want to make all the alerts false positives.  Just the specific event that was investigated.&lt;BR /&gt;&lt;BR /&gt;
Would grouping them into a new class push all like events there?  Or just that event?&lt;/P&gt;

&lt;P&gt;Also, deleting the events, as you mentioned above, would delete all the notable events of the same kind; correct? &lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2016 12:18:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-remove-a-notable-event-from/m-p/203215#M1085</guid>
      <dc:creator>mgrosholz</dc:creator>
      <dc:date>2016-06-13T12:18:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: How to remove a notable event from the "Security Posture" dashboard after investigation?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-remove-a-notable-event-from/m-p/203216#M1086</link>
      <description>&lt;P&gt;You can go through the events singularly, and either mark them as false / true, or delete them.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2016 00:46:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-remove-a-notable-event-from/m-p/203216#M1086</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2016-06-16T00:46:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: How to remove a notable event from the "Security Posture" dashboard after investigation?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-remove-a-notable-event-from/m-p/203217#M1087</link>
      <description>&lt;P&gt;Click the Edit-&amp;gt; Edit Panels in the Security Posture Dashboard.&lt;BR /&gt;
Under the Top Notable Events, click the search report and select Notable-Top Events and select Open in Search. Add &lt;CODE&gt;status_group="New"&lt;/CODE&gt; to this search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| `es_notable_events` | search timeDiff_type=current status_group="New" | stats sparkline(sum(count),30m) as sparkline,sum(count) as count by rule_name | sort 100 - count
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Click Save, Save Dashboard. click Done&lt;BR /&gt;
The Security Posture Dashboard will only show New Notable events&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2016 18:49:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-remove-a-notable-event-from/m-p/203217#M1087</guid>
      <dc:creator>supreetsingh</dc:creator>
      <dc:date>2016-06-16T18:49:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: How to remove a notable event from the "Security Posture" dashboard after investigation?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-remove-a-notable-event-from/m-p/203218#M1088</link>
      <description>&lt;P&gt;What you could try is &lt;CODE&gt;index=notable rule_title="your_notable_event_title" | delete&lt;/CODE&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 15 Jun 2018 09:06:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-remove-a-notable-event-from/m-p/203218#M1088</guid>
      <dc:creator>Azeemering</dc:creator>
      <dc:date>2018-06-15T09:06:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: How to remove a notable event from the "Security Posture" dashboard after investigation?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-remove-a-notable-event-from/m-p/203219#M1089</link>
      <description>&lt;P&gt;This worked for me &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=notable search_name="*your notable title*" | delete 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 28 Nov 2019 05:00:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-remove-a-notable-event-from/m-p/203219#M1089</guid>
      <dc:creator>apcsplunk</dc:creator>
      <dc:date>2019-11-28T05:00:11Z</dc:date>
    </item>
  </channel>
</rss>

