<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Closing Notable Events - Set Close Datetime in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Closing-Notable-Events-Set-Close-Datetime/m-p/675289#M11894</link>
    <description>&lt;P&gt;I'm looking to close out (or delete) all notable events that were created prior to a specific date time.&amp;nbsp; The way they're trying to run reports, it is easier to delete them or close them than it would be to filter them from the reports.&amp;nbsp; Is there a way to use an eval query (or similar) or would it be best to use the API to close them?&amp;nbsp; Or am I SOL and I need to filter from the dashboard / report query level?&lt;/P&gt;</description>
    <pubDate>Wed, 24 Jan 2024 16:47:32 GMT</pubDate>
    <dc:creator>gbam</dc:creator>
    <dc:date>2024-01-24T16:47:32Z</dc:date>
    <item>
      <title>Closing Notable Events - Set Close Datetime</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Closing-Notable-Events-Set-Close-Datetime/m-p/675289#M11894</link>
      <description>&lt;P&gt;I'm looking to close out (or delete) all notable events that were created prior to a specific date time.&amp;nbsp; The way they're trying to run reports, it is easier to delete them or close them than it would be to filter them from the reports.&amp;nbsp; Is there a way to use an eval query (or similar) or would it be best to use the API to close them?&amp;nbsp; Or am I SOL and I need to filter from the dashboard / report query level?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2024 16:47:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Closing-Notable-Events-Set-Close-Datetime/m-p/675289#M11894</guid>
      <dc:creator>gbam</dc:creator>
      <dc:date>2024-01-24T16:47:32Z</dc:date>
    </item>
    <item>
      <title>Re: Closing Notable Events - Set Close Datetime</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Closing-Notable-Events-Set-Close-Datetime/m-p/675656#M11897</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Hi there,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Eval Query for Limited Use:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;While eval queries can modify certain fields,&lt;/SPAN&gt;&lt;SPAN&gt; unfortunately,&lt;/SPAN&gt;&lt;SPAN&gt; deleting or closing notable events directly isn't possible with them.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;API Offers More Power:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The Splunk Search API is your best bet for bulk actions like closing or deleting events.&lt;/SPAN&gt;&lt;SPAN&gt; You can leverage the &lt;/SPAN&gt;delete&lt;SPAN&gt; or &lt;/SPAN&gt;set&lt;SPAN&gt; endpoints to achieve your goal.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Filtering Still an Option:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If using the API feels daunting,&lt;/SPAN&gt;&lt;SPAN&gt; consider refining your dashboard/report queries to exclude events before the specific date.&lt;/SPAN&gt;&lt;SPAN&gt; Filtering might be less efficient for massive datasets,&lt;/SPAN&gt;&lt;SPAN&gt; but it's a reliable route.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Remember:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Deleting is permanent,&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;closing retains some data.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Choose wisely!&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Test your approach on a small sample before applying to all events.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Consult Splunk documentation for detailed API usage:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;lt;invalid URL removed&amp;gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;~ If the reply helps, a Karma upvote would be appreciated&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jan 2024 10:23:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Closing-Notable-Events-Set-Close-Datetime/m-p/675656#M11897</guid>
      <dc:creator>datadevops</dc:creator>
      <dc:date>2024-01-28T10:23:13Z</dc:date>
    </item>
  </channel>
</rss>

