Security

No auto-close when editing events in Splunk ES Incident Review- Is there a configuration setting that will enable this?

mehussain
Engager

After the update to v7.1 of Splunk ES Incident Review channel, when selecting events and choosing Edit Selected, it presents with the popup/overlay window, where we can change the Status (Analyzing, Closed, etc..) and assign ourselves as the Owner. When clicking on Save Changes, the overlay window does not auto-close, and we have to manually click on the Close button. In the previous version this overlay auto-closed and the Incident Review page refreshed after clicking on Save Changes (or Save).

Is there some configuration setting that will enable this once again auto-close after making the Status changes?

Labels (1)
Tags (1)

GlennHD
Engager

I'm also interested in an answer here.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...