Archive

Suppress Notable Event during certain time slot

Path Finder

Is it possible to suppress notable events in Enterprise Security during a specific time window?

i.e. when a server gets rebooted during a specific maintenance window that is the same time every day?

Tags (1)

Explorer

The python variable DEFAULTDROPEXP contains fieldnames to delete when creating a notable event. As it contains **date***, you cannot directly use the date in a notable event suppression. But if you add

| rename date_hour as orig_date_hour, date_minute as orig_date_minute, date_wday as orig_date_wday

to the end of your correlation search, you can use the renamed fields in the notable event suppression:

`get_notable_index` orig_host=YOURHOST orig_date_hour=6 orig_date_minute>=25
0 Karma

Splunk Employee
Splunk Employee

Yes

Take a look at this docs page:
http://docs.splunk.com/Documentation/ES/4.7.4/Admin/Customizenotables#Createandmanagenotableevent_suppressions

j

0 Karma

Explorer

the linked page only shows how to set an Expiration Time. The author wants to suppress eventX between 03:00 and 03:59 every day. I had done this with date_hour in my event_suppression.

On a new installation this does not work anymore because the field date_hour is not added to notable events anymore...

0 Karma