Is it possible to suppress notable events in Enterprise Security during a specific time window?
i.e. when a server gets rebooted during a specific maintenance window that is the same time every day?
The python variable DEFAULT_DROPEXP contains fieldnames to delete when creating a notable event. As it contains date_*, you cannot directly use the date in a notable event suppression. But if you add
| rename date_hour as orig_date_hour, date_minute as orig_date_minute, date_wday as orig_date_wday
to the end of your correlation search, you can use the renamed fields in the notable event suppression:
`get_notable_index` orig_host=YOURHOST orig_date_hour=6 orig_date_minute>=25
Yes
Take a look at this docs page:
http://docs.splunk.com/Documentation/ES/4.7.4/Admin/Customizenotables#Create_and_manage_notable_even...
j
the linked page only shows how to set an Expiration Time. The author wants to suppress eventX between 03:00 and 03:59 every day. I had done this with date_hour in my event_suppression.
On a new installation this does not work anymore because the field date_hour is not added to notable events anymore...