Splunk Enterprise Security

Activity from expired identity keeps triggered although csv has been edited


I have changed the identities.csv and prolonged the expiration of an identity. However, the alert keep getting triggered and stops only when I perform a splunk restart.

Is this normal? Every time I want to change a csv file, do I have to restart the splunk application?

0 Karma


Probably, little more details from your end will help us to assist you.

  • What you mean by - "prolonged the expiration of an identity"?
  • Also, which alert keep getting triggered?
0 Karma


When I say "prolonged the expiration of an identity" I mean the act of editing identities.csv file and for example from expiration date pf 30/08/19 I alter it to 30/10/19.

The triggered alert is "Activity from expired identity".

0 Karma
Get Updates on the Splunk Community!

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...

Cloud Platform | Migrating your Splunk Cloud deployment to Python 3.7

Python 2.7, the last release of Python 2, reached End of Life back on January 1, 2020. As part of our larger ...