Splunk Enterprise Security

Best Practice: Separating Dev/Test and Prod Notables in Incident Review

tfrederick74656
Explorer

I'm looking to provide two separate ES incident review views: one for rules that are live, and another for new rules that are still being tested. I already know I can pre-populate the search box on the incident review dashboard, and then add a new link in the ES navigation bar, but I'm wondering what the best practice is for how to actually filter the notables: Should I prefix all of my non-prod correlation searches with "Dev"? Should I eval in a "prod_status" field? Should I put in an automatic lookup that maps rule_title to dev/test/prod? What's the best approach for making searches easy to separate, and simple to graduate from dev to test to prod?

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...