I have changed the identities.csv and prolonged the expiration of an identity. However, the alert keep getting triggered and stops only when I perform a splunk restart.
Is this normal? Every time I want to change a csv file, do I have to restart the splunk application?
Probably, little more details from your end will help us to assist you.
When I say "prolonged the expiration of an identity" I mean the act of editing identities.csv file and for example from expiration date pf 30/08/19 I alter it to 30/10/19.
The triggered alert is "Activity from expired identity".